competitor-tracking
Warn
Audited by Snyk on Mar 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs monitoring and ingesting public user-generated sources—e.g., competitor blogs, Twitter, Reddit/Stack Overflow mentions, GitHub issues/releases, npm/PyPI trends, Archive.org, and LinkedIn job posts—which the agent is expected to read and use to update battlecards and drive response actions, exposing it to untrusted third-party content (see "What to Track", "Developer Sentiment Monitoring", and "Tools" sections).
Audit Metadata