integrating-agent-auth

Warn

Audited by Snyk on Mar 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's workflow (Step 4 "Call the third-party API" and the "Building agents" examples) explicitly fetches user-generated content from third-party connectors (e.g., Gmail via the Gmail API, and it mentions Slack/Notion/calendar connectors) and has agents read/summarize that content, which could contain untrusted instructions that influence agent decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 28, 2026, 06:40 PM
Issues
1