affiliate-blog-builder

Warn

Audited by Snyk on Mar 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflow explicitly instructs the agent to run web_search/web_browse on public sites (e.g., "Use web_search to find 2-3 top competitors" and "Use web_search for '[target keyword]' related searches / People Also Ask" in SKILL.md) so the agent will ingest and act on untrusted third‑party web content (G2/Capterra/search results) that can materially influence competitor selection, keywords, pricing, and CTA placement.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 20, 2026, 07:32 AM
Issues
1