gr-competitor

Warn

Audited by Snyk on May 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly fetches and extracts content from arbitrary public websites (actionbook extract , blog/index pages, landing/pricing pages and Wayback Machine) and then ingests and synthesizes that untrusted third‑party content into reports and recommendations (see the SKILL.md calling actionbook extract and the prompt templates), so external page content could indirectly inject instructions affecting agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 13, 2026, 04:09 AM
Issues
1