instagram-expert
Warn
Audited by Snyk on Apr 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill's reference docs (e.g., references/insights-comments-api.md and references/graph-api.md) explicitly instruct fetching public, user-generated Instagram content (GET /{ig-media-id}/comments, GET /{ig-user-id}/conversations, hashtag searches, Business Discovery, webhooks, etc.), which the agent would read/interpret and could directly drive actions like replying to comments or sending messages, exposing it to untrusted third‑party content that could carry indirect prompt injections.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata