deep-research
Warn
Audited by Snyk on May 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill clearly ingests and interprets public third-party content as part of its required Phase 2 workflow—e.g., bibliography_agent's systematic search and Step 4.5 Semantic Scholar deduplication (and v3.9.0 triangulation calling Semantic Scholar / OpenAlex / Crossref) plus full-text screening and monitoring_agent's Retraction Watch / PubMed / Google Scholar alerts—which can materially influence synthesis, meta-analysis, and subsequent agent actions, creating a surface for indirect prompt injection.
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata