end-to-end-study

Warn

Audited by Snyk on May 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to use WebSearch/WebFetch to pull and distil open/public third‑party content (e.g., Phase 2: "Use WebSearch + bioRxiv / PubMed MCP"; Phase 3 and references/author-instructions.md: "fetch the target journal's author instructions" with canonical URLs; references/open-datasets.md includes public dataset URLs and a Springer supplementary XLSX link), and those fetched, untrusted web pages and dataset files are read and interpreted to drive journal selection, manuscript formatting, methods checklist, and analysis decisions—meeting the criteria for indirect prompt-injection risk.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill explicitly calls WebFetch at runtime to pull and distil journal author instructions (which then drive the agent's writing prompts), e.g. it lists and will fetch https://www.nature.com/ncomms/submission-guidelines to produce manuscript/JOURNAL.md, so external page content directly controls prompts used by the agent.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 2, 2026, 03:31 PM
Issues
2
Security Audit — snyk — end-to-end-study