huggingface-datasets
Warn
Audited by Snyk on Aug 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s required runtime workflow calls Hugging Face Dataset Viewer endpoints like
/first-rows,/rows,/search(with user-providedquery), and/filter, which return dataset row text authored by third parties, so an outsider can cause the agent to ingest that free text by providing a dataset selection/split to browse/search.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata