copying-endpoints-across-projects
Warn
Audited by Snyk on Jul 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). SKILL.md step 2/6 requires reading and re-sending the source endpoint’s full
queryviaendpoint-getand then passing that captured text verbatim intoendpoint-create(outsider-authored endpoint query/config could be attacker-controlled free text that enters the agent’s LLM context during summarization and prompt construction).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata