mckinsey-market-research-deck

Warn

Audited by Snyk on Aug 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). [Exclusion] The skill’s required runtime workflow ingests only first-party structured outputs it itself generates (e.g., <brand>-data.json and verified _decision_*.json), while any outsider-authored text is treated only as data sourced from explicitly fetched “sourceUrl” items via WebSearch/WebFetch under the source bar rather than being passively monitored from an ongoing queue/feed or read without selecting/fetching specific items.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 4, 2026, 10:39 AM
Issues
1
Security Audit — snyk — mckinsey-market-research-deck