openalex
Warn
Audited by Snyk on May 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly fetches and ingests results from the public OpenAlex API (via tools/openalex_fetch.py and the "Execute Search" step) and then parses and presents third-party fields like abstracts, OA URLs, topics and keywords (Step 4/Step 5), so untrusted public content can be read and influence follow-up actions/queries.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata