data-scraper-agent
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the runtime path
scraper/main.py→SOURCES→fetch_fn()→items→ai/pipeline.py::_build_prompt()→ai/client.py::generate(prompt), the agent passes scraped page/API/RSS text (outsider-authored content from the selected public data sources) into Gemini enrichment without constraining or sanitizing it to trusted content.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The GitHub Actions workflow includes runtime "uses" of external actions (actions/checkout@v4 and actions/setup-python@v5) which the runner fetches and executes as remote code during job execution, creating a dependency on externally-run code (actions/checkout@v4, actions/setup-python@v5).
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata