us-program-research
Warn
Audited by Snyk on Mar 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Phase 2/Phase 3 workflow and references/subagent-prompts.md and references/research-sources.md explicitly require launching web searches and subagents that fetch and ingest untrusted user-generated sources (e.g., Reddit, Niche, GMAT Club, GradCafe) and then use those reviews/scraped content to compute student satisfaction and adaptive scorecards that materially drive ranking and recommended actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata