startup-validator
Warn
Audited by Snyk on Feb 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly requires performing 10–15+ web searches and instructs using web_fetch to read full articles from public sources (see "Always use at least 10-15 web searches" and "CRITICAL: Use
web_fetchto read full articles" in SKILL.md and references/research_templates.md which list public sites like TechCrunch, Crunchbase, Stack Overflow, Product Hunt), so the agent will fetch and interpret untrusted third‑party web content.
Audit Metadata