ml-paper-writing
Warn
Audited by Snyk on May 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL explicitly instructs the agent to search and programmatically fetch content from open/public sources (e.g., Exa MCP, Semantic Scholar, CrossRef, arXiv DOI fetch) as part of the mandatory "Citation Workflow" and "Step 4: Search for Additional Literature", so it ingests untrusted third‑party content that can influence drafting and tool actions.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's mandatory citation workflow instructs the agent to programmatically fetch bibliographic metadata/BibTeX at runtime from external APIs (e.g., https://doi.org, https://api.semanticscholar.org, https://www.crossref.org, https://info.arxiv.org), which will be injected into the model context and thus directly control the agent's outputs.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata