NYC

flask

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill includes app/services/external_api.py (ExternalAPIService) which performs requests to external APIs and a /proxy/data route that proxies and returns that external JSON, so it clearly fetches and ingests untrusted third-party content for the agent to read/interpret.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:36 PM