unclawg-discover

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and ingests public, user-generated content from open third-party sources (e.g., Reddit, Hacker News, Twitter/X, LinkedIn, TikTok, Instagram, YouTube) via the Phase 3 "Run Discovery" flow and scripts like scripts/search_reddit.sh, scripts/search_twitter.sh, and scripts/search_linkedin.sh, and that content is parsed and used to score candidates and drive reply_strategy/handoff decisions, so untrusted posts could indirectly inject instructions that change agent behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 02:39 PM