orchestrating-swarms

Warn

Audited by Snyk on Apr 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly instructs research and design agents to fetch and ingest external content (e.g., Pattern 4 "Research + Implementation" uses research.content, the "claude-code-guide" agent lists webfetch/google_search, and the Design Agent references comparing with a Figma URL), so untrusted third-party webpages/URLs can be read and their content directly drives subsequent agent prompts and actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 2, 2026, 03:05 PM
Issues
1
Security Audit — snyk — orchestrating-swarms