instagram-research
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). SKILL.md/scripts/crawlora.sh only call first-party Crawlora API endpoints with user-supplied path params (e.g.,
/instagram/profile/{username},/instagram/reels/{id},/instagram/post/{id}/{post_id}) and do not implement any free-text ingestion/search of outsider-authored content beyond fetching specific public Instagram records requested by the user.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata