swiggy-mcp-dineout
Warn
Audited by Snyk on Sep 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Restaurant search results and details from Swiggy Dineout contain outsider-authored text descriptions and menus, but the agent only searches/fetches specific items based on user input.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill documentation describes tools and workflows for booking restaurant tables via Swiggy Dineout, which explicitly includes creating carts, handling payment options, and initiating UPI payments for paid restaurant deals (
create_cart,get_payment_options,book_tablewith UPI). This constitutes a direct financial execution capability via payment gateway/UPI integration.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata