letta-development-guide

Warn

Audited by Snyk on Apr 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's tool documentation (references/tool-patterns.md "Custom Tool Development" example) shows creating a custom tool that performs requests.get against a public URL (https://wttr.in) so agents can fetch and ingest arbitrary third‑party web content whose returned text is consumed as tool output and can influence agent decisions and subsequent tool use.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 23, 2026, 06:37 AM
Issues
1