comprehensive-research-agent
Warn
Audited by Snyk on May 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly requires web research using search/read_url/fetch (see "When to Activate" and examples that fetch public URLs, including attempts to read Anthropic docs), so the agent will ingest and act on untrusted public web content as part of its workflow, enabling indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata