deep-research
Warn
Audited by Snyk on May 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly requires web-enabled research and instructs the agent to fetch and read public third-party sources (see "Capability check", "Source policy", and "Step 5
- Depth and verification pass" which call out public sites, community discussion, live APIs and URLs), so the agent will ingest untrusted user-generated or open-web content that can materially change decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata