apply-dossier-evaluator
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow ingests the applicant’s free-form dossier content (CV/SOP/research statement, transcript text, publication lists, and recommender metadata) provided by the user, and then scores it across dimensions using that evidence.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill explicitly requires live web verification and instructs the agent to fetch program/professor pages at runtime (e.g., https://vef2.org/, https://daad.de, https://fulbright.gov, https://portal.core.edu.au/conf-ranks/, https://enic-naric.net/, https://wes.org/) and to "fetch this live per run", meaning those external pages would be retrieved and injected into the evaluator's runtime context to drive scoring decisions.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata