content-source-aggregator
Warn
Audited by Snyk on Mar 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). This skill directly fetches and parses untrusted, user-generated content from multiple public sources (e.g., X via https://syndication.twitter.com/srv/timeline-profile/screen-name/{username}, Reddit via https://api.pullpush.io/reddit/..., YouTube RSS, Bilibili, GitHub, etc.) into a standardized hotpool JSON that is consumed by downstream research agents for topic selection, so third‑party content can materially influence agent decisions.
Audit Metadata