agent-collaboration
Warn
Audited by Snyk on Apr 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Researcher role (SKILL.md "Researcher" section and agents/researcher.md) explicitly performs web search and uses WebFetch to ingest public web pages and documentation, and those research outputs are consumed by the Planner to make decisions that drive subsequent agent actions—exposing the agent to untrusted third‑party content that could carry indirect prompt injections.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata