ai-elements
Warn
Audited by Snyk on Mar 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill’s Agent example (references/agent.md) explicitly exposes tools like readUrl ("Read and parse content from a URL") and webSearch and shows them added to AgentTools, meaning the agent is expected to fetch and interpret arbitrary public URLs/search results (untrusted third‑party content) as part of its workflow, which can materially influence actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata