case-radar

Warn

Audited by Snyk on May 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly scans and ingests public third‑party content (via WebSearch/Agent scan, curl/gh API pulls from public GitHub raw files, and agent-browser open/screenshot of arbitrary public pages including marketplaces, blogs, and YouTube) as core runtime inputs and then uses that content to decide recon/capture actions and what to include in the HTML output, so untrusted user‑generated web content could indirectly inject instructions that change agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 06:54 AM
Issues
1
Security Audit — snyk — case-radar