quick-research
Warn
Audited by Snyk on May 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly performs open-web searches (firecrawl + Tavily) and then scrapes the top 3 results with "firecrawl scrape" in Step 2 READ, so the agent ingests untrusted third‑party web content that it must interpret and use to generate answers.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata