flow-discover
Warn
Audited by Snyk on May 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). Yes — the skill explicitly invokes live web research (Perplexity live web search) and launches orchestrate.sh probe/probe-single and CLI providers that fetch and return external URLs/content (see "Perplexity
- Live web search" and the "When discover workflow fetches external URLs..." / security framing sections), which the agent is required to read and synthesize into decisions, so untrusted third‑party content can materially influence actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata