semanticscholar-skill
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In s2.py, the outsider-controlled user query is incorporated into the Semantic Scholar API request bodies/params via build_bool_query()/search_* and the agent then ingests first-party-but-untrusted-to-the-user free text fields like paper titles/abstracts/TLDR and formats them for output.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata