autonomous-workflow
Warn
Audited by Snyk on May 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's planner is explicitly allowed to use WebFetch/WebSearch (see CLAUDE.md "Keep the planner high-level" table) and SKILL.md/README describe Phase 1 research/Explore sub-agents and list external "Research Sources" URLs, so the agent can fetch and act on untrusted public web content that can influence plans and downstream actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata