content-calendar
Warn
Audited by Snyk on Mar 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Phase 2 Research explicitly instructs the agent to scrape/browse competitor public profiles (via Firecrawl and Playwright) and run SerpApi searches to ingest user-generated, open-web content and then use those findings to adjust pillar ratios, topics, and the calendar—i.e., third-party posts/search results are read and directly influence decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata