AnnualReports

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill fetches and parses open/public third‑party content (the upstream README from https://raw.githubusercontent.com/... in Tools/UpdateSources.ts and arbitrary report pages/URLs fetched by Tools/FetchReport.ts via fetchReportPage), treats that untrusted/web‑hosted content as input to parsing, summarization, and source updates, and then uses those results to drive analysis and tool actions—exposing the agent to potential indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 12:19 PM
Issues
1