research-lit
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's workflow (Step 1: Search external and Source Table) explicitly fetches and ingests content from open/public third-party sources — e.g., WebSearch/Exa web extraction, arXiv API (and optional PDF downloads), Semantic Scholar, DeepXiv, Gemini, and OpenAlex — and then reads and analyzes that fetched metadata/text to drive ranking, downloads, wiki ingest, and synthesis, so untrusted web content can directly influence tool use and next actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata