money-discover
Warn
Audited by Snyk on May 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow explicitly instructs the agent to search and ingest content from open/public third-party sources (e.g., "Phase 2: Trend Analysis" — Product Hunt, Hacker News, X/Twitter, Reddit; "Problem Mining" — Reddit, forums, review sites) and to "Back every claim with data from web research," so untrusted user-generated content will be read and used to drive decisions, creating a clear avenue for indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata