ic-dashboard
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs the agent to fetch and parse public REST APIs (e.g., https://ic-api.internetcomputer.org, https://icrc-api.internetcomputer.org, https://sns-api.internetcomputer.org) that return user-generated/untrusted data (such as SNS proposals and ledger entries) which the agent is expected to read and use (pagination, content inspection) as part of its workflow, creating a clear vector for indirect prompt injection.
Audit Metadata