create-peer-review
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly downloads arXiv papers ("review_arxiv_cmd: Downloads paper via ar5iv HTML" and ingest/benchmark flows) and feeds the untrusted paper text into LLM prompts (see _build_review_prompt, tier2_teacher_review, and _get_author_reviews), so arbitrary public web/user-authored content can be read/interpreted and materially influence reviews and downstream actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata