anndata-data-structure

Warn

Audited by Snyk on Apr 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly instructs the agent to load external dataset files and cloud Zarr stores (e.g., SKILL.md Core API I/O examples like ad.read_h5ad("data.h5ad"), the batch-file glob in Workflow 2, and references/data_structure_io.md "Zarr Advanced Patterns" showing s3:// and gs:// stores), and those workflows consume and act on metadata (adata.obs, adata.uns["neighbors"]["params"]) to drive filtering and processing, so untrusted third‑party files could indirectly inject instructions that change agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 28, 2026, 02:13 PM
Issues
1