jk-trial-data-scoping

Warn

Audited by Snyk on Jun 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). ClinicalTrials.gov v2 study search is performed at runtime via scripts/clinical_trials.py calling https://clinicaltrials.gov/api/v2/studies?... and then ingesting the returned study fields (e.g., briefSummary, conditions, outcomes) into the generated JSON/table artifacts and thus into the agent’s LLM context as readable text.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 23, 2026, 12:21 PM
Issues
1
Security Audit — snyk — jk-trial-data-scoping