find-sources
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow in SKILL.md instructs downloading/probing candidate sources from external URLs (e.g., API endpoints, bulk files, and search pages) and then reading the returned HTML/CSV/text at step 2/3, so an outsider who can cause the workflow to probe attacker-controlled URLs or records could supply poison free text for the LLM to ingest.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata