use-subagents

Warn

Audited by Snyk on Jul 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.78). The workflow delegates to subagents (e.g., the “research” role explicitly says to “fetch and verify primary sources” from external sites), which can ingest outsider-authored free-form web page text into the agent’s LLM context at runtime via runtime retrieval/web-fetch tools.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 23, 2026, 06:57 PM
Issues
1
Security Audit — snyk — use-subagents