price-drop-watch
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Within the required workflow, the agent performs “Search each source” (Amazon/Walmart/others) for a user-provided product string and then uses fields from the resulting API responses, but the skill does not indicate it reads outsider-authored free text from a user-submitted queue/feed, tickets, or arbitrary external pages without first selecting a specific product listing.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly instructs using the hosted MCP endpoint which is contacted at runtime to register and expose agent "tools" that directly control agent capabilities and behavior (https://mcp.scavio.dev/mcp).
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata