testing-tool-evaluator
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). SKILL.md includes a _test_performance implementation that performs requests.get(api_endpoint) against arbitrary tool_config API endpoints, so the agent fetches and acts on third-party/untrusted web content (response timing/content) which directly influences scoring and recommendations.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata