papertrail
Warn
Audited by Snyk on May 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md shows the agent using paperctl pull/search to fetch and read logs from SolarWinds Observability (and even queries a public Taskcluster API like https://firefox-ci-tc.services.mozilla.com in the "Common workflows"), meaning it ingests untrusted third-party log/content which the agent is expected to interpret and that can influence subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata