deepsearch
Warn
Audited by Snyk on Mar 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly depends on a web-search skill that runs
python scripts/web_search.py "<query>"to fetch and append real web search results into thefindingsarray, and those untrusted public web contents are read by the LLM to decide nextSearchTopic and drive further searches and analysis.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata