cdc-voucher-locator-skill
Warn
Audited by Snyk on Jun 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text is ingested via runtime HTTP fetches of public CDN JSON files (
https://prd-tmp.cdn.gowhere.gov.sg/.../data.gzipanddata_supermarket.json) and OneMap geocoding responses (https://www.onemap.gov.sg/api/common/elastic/search?...), whosename/addressfields are treated as readable text and fed into the agent’s context through the script’s JSON output.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata