copy
Warn
Audited by Snyk on May 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required frameworks (copy-frameworks.md, which SKILL.md mandates the agent read before writing) explicitly instruct the agent to mine and use public, user-generated sources — e.g., "Where to Mine Market Voice" lists YouTube comments, Reddit, Amazon reviews, Facebook groups, TikTok and niche forums — meaning the agent is expected to fetch and interpret untrusted third-party content that can materially influence its copywriting decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata