NYC

literature-review

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly ingests and processes open/public third‑party content (e.g., "gget search pubmed" and "gget search biorxiv", arXiv via direct API, Semantic Scholar/Google Scholar scraping, and CrossRef/doi.org lookups in scripts/verify_citations.py), and the workflow requires the agent to read/interpret abstracts and full texts from those public sources, so it is exposed to untrusted user-generated third‑party content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:40 AM