travel-promos-argentina
Warn
Audited by Snyk on Feb 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to fetch and parse promos from the public API at https://anduin.ferminrp.com/api/v1/promos (with data.source/permalink pointing to external origins), and the agent must read and apply that untrusted third‑party content to filter, rank, and decide which promotions to present.
Audit Metadata