Research

Warn

Audited by Snyk on Aug 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill’s runtime path for outsider-authored text is the sentiment routing + community scrapers step: Workflows/StandardResearch.md Step 0 (reads ../SourceRoutingProtocol.md) and Step 2 callouts fetch Reddit/X/YouTube comments via curl/API and pass the resulting comment text into the LLM for synthesis (e.g., https://www.reddit.com/r/{sub}/top.json..., thread/comment JSON, and X recent-search results).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 06:48 PM
Issues
1
Security Audit — snyk — Research