osint-research
Warn
Audited by Snyk on May 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly fetches and scrapes public third‑party content (e.g., crt.sh via curl, Wayback/Archive.org, internetdb.shodan.io, GitHub code search, and Tavily/Firecrawl scrapes described in SKILL.md Phase 1/2) and then ingests and interprets those untrusted results (after inbound-filter/secret-redactor) as part of its findings extraction and synthesis, so external page content can materially influence priorities, follow‑up scrapes, and report actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata