IC Dashboard APIs
Warn
Audited by Snyk on Feb 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's core workflow explicitly directs the agent to fetch and parse public external APIs and OpenAPI specs (e.g., https://ic-api.internetcomputer.org/api/v3/openapi.json and https://icrc-api.internetcomputer.org/api/v2/ledgers) so untrusted third‑party responses are read and used to drive pagination and subsequent requests, allowing that content to materially influence agent actions.
Audit Metadata