building-omnistudio-integration-procedure
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's required workflow and references (SKILL.md and references/element-types.md) explicitly define HTTP Action callouts to external APIs (e.g., the "path": "https://api.example.com/v1/accounts" example) and instruct the IP to parse status codes and response bodies and branch/act on them, so untrusted third‑party API responses can directly influence procedure behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata