anysite-competitor-intelligence

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly scrapes and ingests open/public third-party content — e.g., parse_webpage("https://competitor.com"), get_sitemap, search_reddit_posts, get_twitter_user_posts, get_instagram_user_posts and similar MCP tools — and instructs the agent to read and analyze that user-generated/untrusted content as part of its workflows, enabling indirect prompt injection.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 10:54 AM