literature-review
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill explicitly ingests and processes open/public third‑party content (e.g., "gget search pubmed" and "gget search biorxiv", arXiv via direct API, Semantic Scholar/Google Scholar scraping, and CrossRef/doi.org lookups in scripts/verify_citations.py), and the workflow requires the agent to read/interpret abstracts and full texts from those public sources, so it is exposed to untrusted user-generated third‑party content.
Audit Metadata