add-mcp-from-remote-url
Warn
Audited by Snyk on Aug 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow inspects and registers a user-supplied remote MCP server URL via
inspect_mcp_candidateandregister_remote_mcp, meaning the agent actively fetches content from an arbitrary, outsider-controlled web endpoint chosen by the user.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata