ds-report-pdf
Warn
Audited by Snyk on Mar 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches live data from third-party platforms via the Dataslayer MCP (Step 2: Google Ads, Search Console, GA4, Meta, LinkedIn) and even downloads arbitrary logo URLs ("Use the logo at https://..."), and that untrusted content is parsed and used to generate analyses and drive decisions/actions in Steps 3–5, so external content can materially influence the agent's behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata