data-scientist-analyst
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Skill “Data Scientist Analyst” reads dataset files from the user’s project directory (e.g.,
dataset.csv) at runtime viascripts/run_stat_analysis.py --input ..., and those CSV contents are outsider-authored free text if the attacker can supply/post a CSV into the project/workspace.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata