free-tool-research
Warn
Audited by Snyk on Apr 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md workflow (Steps 2–4: "Search the web", "Research Competitor Free Tools", and "Use web search to find...") explicitly directs the agent to fetch and read public competitor pages and search results (e.g., /tools, /free-tools, Google autocomplete), meaning it ingests untrusted third‑party web content that can materially influence its recommendations.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata