ieee-search-mcp

Warn

Audited by Snyk on Mar 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill's SKILL.md explicitly instructs the agent to open and interact with external library and proxy web pages (e.g., the profile fields library_home and proxy_ieee_home in assets/school_profiles.example.json and steps like "Open library_home, verify login state" and "enter IEEE from library entry"), so it fetches and interprets untrusted third‑party web content at runtime which can change navigation and tool actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 7, 2026, 01:32 PM