data-research

Warn

Audited by Snyk on Apr 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly ingests public third-party web content in "Phase 2: Search Sources" (web via search: public filings, press releases, regulatory data) and then reads/parses those saved raw sources with deterministic extraction and LLM fallbacks (Phase 4/5), so untrusted third-party pages can influence extraction results and subsequent tracker updates.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 15, 2026, 06:37 AM
Issues
1