gif-search
Warn
Audited by Snyk on Jun 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill calls the Tenor API at runtime and ingests the JSON response (including titles/URLs) into the agent via the user’s
curl ... | jq ...pipeline, where Tenor is an external public content provider (outsider-authored text).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata