multi-provider-llm-proxy-debugging

Warn

Audited by Snyk on Apr 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md shows the proxy directly consumes and may "pipe" responses and error bodies from external LLM providers (e.g., Google AI Studio, OpenRouter, Claude) into the bot/consumer—meaning untrusted third-party provider responses are read/interpreted at runtime and can materially change agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 16, 2026, 08:51 AM
Issues
1