n8n-skills
Warn
Audited by Snyk on Mar 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill documentation (SKILL.md and resources/INDEX.md) and community node pages (e.g., resources/community/@mendable/n8n-nodes-firecrawl.md, resources/community/@apify/n8n-nodes-apify.md) explicitly describe workflows and nodes that fetch/scrape public, user-generated web content (HTTP Request, Apify, Firecrawl, Puppeteer, RSS, Reddit, YouTube transcripts, etc.) and instruct building AI agents and RAG/QA chains that consume and act on that content, which clearly permits untrusted third-party content to influence agent actions and enable indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata