check-exploit
Warn
Audited by Snyk on Aug 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/multi-search.py, attacker-controlled user input (query/CVE/nmap path) is used to build and output URLs for multiple online exploit sources (Exploit-DB, Shodan CVEDB, Vulners, Sploitus, PacketStorm, search-vulns, Sploitify) which the workflow is intended to open/drill into, exposing the agent to free text from outsider-authored pages.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata