survicate
Warn
Audited by Snyk on May 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md shows the agent uses the Membrane CLI to connect to Survicate and run actions that retrieve Survicate data (e.g., survey responses) via commands like "membrane action run ...", which are user-generated/untrusted third-party contents the agent is expected to read and could influence subsequent decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata