competitive-intelligence

Warn

Audited by Snyk on Feb 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly instructs using WebSearch/WebFetch to ingest and analyze public third-party content—listing company websites, blogs, press releases, social media (LinkedIn/Twitter), review sites (G2, Capterra, TrustRadius) and forums/Reddit in "Method 1/2" and core workflows—and then uses that content to drive analysis and recommendations, which satisfies the criteria for exposure to untrusted third-party content that could enable indirect prompt injection.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 24, 2026, 03:01 AM