building-omnistudio-integration-procedure

Warn

Audited by Snyk on May 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's required workflow and references (SKILL.md and references/element-types.md) explicitly define HTTP Action callouts to external APIs (e.g., the "path": "https://api.example.com/v1/accounts" example) and instruct the IP to parse status codes and response bodies and branch/act on them, so untrusted third‑party API responses can directly influence procedure behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 02:46 PM
Issues
1