intellexer-api
Warn
Audited by Snyk on Apr 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly lists actions that fetch and process arbitrary public URLs (e.g., "parse-document-url", "summarize-url", "get-topics-from-url", "compare-urls") and documents the use of the Membrane proxy via
membrane requestto retrieve external content, so the agent will ingest untrusted third-party web content that can influence downstream actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata