regulomedb-database

Warn

Audited by Snyk on Apr 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill's required workflows repeatedly POST/GET to the public RegulomeDB API endpoints (e.g., https://regulomedb.org/regulome-search/, /regulome-summary/, /regulome-datasets/) and directly ingest and interpret the returned JSON (peaks, eqtls, score fields) to drive scoring, filtering, and downstream actions, exposing the agent to untrusted third‑party web content that can materially influence behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 28, 2026, 02:13 PM
Issues
1
Security Audit — snyk — regulomedb-database