orchestrating-swarms
Warn
Audited by Snyk on May 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's runtime guidance (e.g., references/agent-types.md's "claude-code-guide" which allows WebFetch/WebSearch, and references/orchestration-patterns.md which instructs agents to "Compare implementation with Figma at [URL]" and to pass research.content from a research Task into an implementation Task) explicitly requires agents to fetch and consume external URLs/public web content and then act on those results, so untrusted third‑party content can materially influence subsequent tool use and decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata