literature-review
Warn
Audited by Snyk on Sep 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The agent skill executes academic search queries and processes retrieved bibliographic metadata, papers, and abstracts, which are user/third-party indexed scholarly works but do not constitute unauthenticated outsider-authored submission feeds (like issues or support tickets); however, since the agent searches and fetches arbitrary web/scholarly content via APIs and search tools without a strict pre-selected item constraint, it falls under active search/fetch of external content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata