ask-many-models

Warn

Audited by Snyk on Mar 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly runs "Deep Research" queries that use web-search tools and background research APIs (see SKILL.md "Deep Research" section and scripts/deep-research-query.ts which calls OpenAI/Gemini deep research with web_search and returns citations/URLs, and scripts/query.ts which attaches provider web_search/url_context tools), so it fetches and ingests untrusted public web content that is then read and synthesised as part of the workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 7, 2026, 08:08 PM