agent-native-architecture
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly exposes tools that fetch and ingest open web and third-party user content—e.g., call_api/fetch_url/web_search/web_fetch in references/mcp-tool-design.md and other docs, plus the "Discord feedback bot" example in references/architecture-patterns.md—so the agent is expected to read and interpret untrusted public or user-generated content as part of its workflows.
Audit Metadata