orchestrating-swarms

Warn

Audited by Snyk on May 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's runtime guidance (e.g., references/agent-types.md's "claude-code-guide" which allows WebFetch/WebSearch, and references/orchestration-patterns.md which instructs agents to "Compare implementation with Figma at [URL]" and to pass research.content from a research Task into an implementation Task) explicitly requires agents to fetch and consume external URLs/public web content and then act on those results, so untrusted third‑party content can materially influence subsequent tool use and decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 7, 2026, 04:21 PM
Issues
1