brand-mention-monitor
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill “brand-mention-monitor” runs web/social discovery and then extracts full page/thread content for high-signal candidate mentions (e.g., Reddit/LinkedIn/G2/etc.) written by outsiders, so the workflow ingests attacker-authored free text at runtime without needing a prior user-selected item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata