ai-agent-design
Warn
Audited by Snyk on Apr 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly defines and uses a "search_web" tool (and ReAct examples like "Action: search_web[...]") and the references (e.g., references/agent-patterns.md with "read_page") instruct the agent to fetch and incorporate web/search results into its observation context, so untrusted public web content can be read and materially influence subsequent planning and tool selection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata