perplexity-search
Warn
Audited by Snyk on Jun 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill sends the user-provided
queryas the solemessages[0].contentto the Perplexity model via LiteLLM/OpenRouter; Perplexity then performs runtime web retrieval and incorporates fetched public page text into the model’s generated response, which is returned and thus becomes LLM context/output (outsider-authored web content path: Perplexity web browsing → model context →response.choices[0].message.content).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata