command-research
Warn
Audited by Snyk on Aug 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow explicitly dispatches an
app-researchersub-agent that performsWebSearch + WebFetchand then returns “top findings” with “named sources,” meaning the agent will ingest arbitrary free text from outsider-authored web pages/content it fetches.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata