x-api
Warn
Audited by Snyk on Jun 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required runtime workflow uses X API calls (e.g.,
/2/tweets/search/recent,/2/users/.../tweets,/2/users/by/username) that return third-party tweet/user text from X, which the agent would ingest into the LLM context as readable JSON fields like tweet text/description—an outsider-authored free-text source.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata