agent-builder

Warn

Audited by Snyk on May 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs agents to use external "skills" (e.g., "twitter", "coingecko") and to "search, fetch, analyze" public content — see SKILL.md/team workflow examples ("btc-fetcher" workers: "Fetch BTC tweets") and the daemon/scheduled templates (templates/daemon_run.py and templates/scheduled_run.py) that drive agents to ingest and act on third‑party, user‑generated web content, which can materially influence subsequent tool use and decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 12, 2026, 01:04 AM
Issues
1