positioning-basics
Warn
Audited by Snyk on Mar 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's Phase 2 "Competitive Mapping" explicitly instructs the agent to run web_search('[Company/category] competitors alternatives 2026') to fetch competitor names from the open web, which is untrusted third-party content the agent must read and use to shape positioning decisions, so it exposes the agent to indirect prompt injection risk.
Audit Metadata