canary
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill ingests outsider-authored free text via runtime HTTP responses by
curl-fetching user-supplied${URL}endpoints like/sitemap.xmland/robots.txt(Phase 3) and repeatedly fetching page content/health data withcurlin the monitoring loop (Phase 4), where those responses can contain arbitrary text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata