create-paper
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill autonomously fetches and ingests open web content (e.g., the DOGPILE_SCRIPT invoked in analysis._run_dogpile_research, the /arxiv search and /arxiv learn flows described in Stage 3–4 of SKILL.md, and the noted /surf web access for Horus), treats those untrusted third‑party sources (arXiv, GitHub, public docs) as input for knowledge extraction, and then uses those extractions (paper Q&A, research_context, paper_excerpts) to ground and drive generation and verification (RAG grounding, citation/claim-graph), so untrusted content can materially change agent decisions and outputs.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill fetches arXiv content at runtime (e.g., https://export.arxiv.org/api/query?id_list={clean_id}) and uses the downloaded papers/extractions to build RAG grounding and mimic-style prompts that are injected into the model context, so remote content can directly control generation prompts.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata