create-paper

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill autonomously fetches and ingests open web content (e.g., the DOGPILE_SCRIPT invoked in analysis._run_dogpile_research, the /arxiv search and /arxiv learn flows described in Stage 3–4 of SKILL.md, and the noted /surf web access for Horus), treats those untrusted third‑party sources (arXiv, GitHub, public docs) as input for knowledge extraction, and then uses those extractions (paper Q&A, research_context, paper_excerpts) to ground and drive generation and verification (RAG grounding, citation/claim-graph), so untrusted content can materially change agent decisions and outputs.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill fetches arXiv content at runtime (e.g., https://export.arxiv.org/api/query?id_list={clean_id}) and uses the downloaded papers/extractions to build RAG grounding and mimic-style prompts that are injected into the model context, so remote content can directly control generation prompts.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:36 AM
Issues
2
Security Audit — snyk — create-paper