discover-by-domain
Warn
Audited by Snyk on Apr 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). This skill explicitly performs "WebSearch + WebFetch" and instructs the agent to ingest open-web sources (industry articles, funding announcements, conference/sponsor lists, LinkedIn filters, HN/Reddit threads) in Step 3 of SKILL.md to enumerate companies, so untrusted third-party content is read and used to drive which companies are included and the resulting actions/notes.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata