open-meteo
Warn
Audited by Snyk on Mar 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill explicitly calls public Open‑Meteo endpoints (e.g., the Geocoding API at https://geocoding-api.open-meteo.com/v1/search documented in SKILL.md and demonstrated in references/examples.md), ingests those third‑party responses (geocoding results/timezones) into its workflow and uses them to drive subsequent requests and decisions, which meets the criteria for exposure to untrusted public third‑party content.
Audit Metadata