onboarding

Warn

Audited by Snyk on May 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL's Step 0 Search Strategy and enforcement (SKILL.md) require the agent/analyst to perform web research using public sources — e.g., "Google News", "BBC", "LinkedIn", "Companies House", "OFAC", "EU Consolidated Sanctions List" — and MCP Integration even references a browser ("Claude in Chrome"), meaning the agent is expected to fetch and interpret untrusted third‑party web content that can directly affect proceed/escalate decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 7, 2026, 01:28 PM
Issues
1
Security Audit — snyk — onboarding