ai-security-analyst
Warn
Audited by Snyk on Mar 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md Phase 2 "Prompt Injection Assessment" explicitly requires testing with external/untrusted sources — e.g., "Embed instructions in documents the AI is asked to summarize" and "Inject via web page content fetched by AI browser tool" — which means the agent will ingest and interpret public third‑party content that could carry indirect prompt injections.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata