aris-semantic-scholar

Warn

Audited by Snyk on May 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill directly queries the public Semantic Scholar API (https://api.semanticscholar.org/graph/v1 and related openAccessPdf/DOI URLs) per the SKILL.md search/fetch workflow (Steps 2, 3, 5, 6) and ingests abstracts, TLDRs, citation counts and PDF links which the agent uses to rank, filter, and decide follow-up actions, exposing it to untrusted third-party content that could carry indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 6, 2026, 01:43 AM
Issues
1
Security Audit — snyk — aris-semantic-scholar