research-curator
Warn
Audited by Snyk on May 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly accepts and parses arbitrary public URLs (Default Mode: "extract the URL" then spawn an agent with prompt "Research and create an entry for: {URL}" and Batch Mode: "Parse all tokens after --batch matching https?://") and even uses WebSearch for canonical URLs in Fallback Mode, so it ingests untrusted third‑party web content which the agents read and act on (creating files, spawning follow‑on agents), exposing the orchestrator to indirect prompt injection from those pages.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata