juma-cro-audit
Warn
Audited by Snyk on Apr 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL explicitly requires accessing and reviewing third-party content — "Access to the live website for manual walkthrough" and external analytics/heatmap data (Google Analytics GA4, Hotjar/Microsoft Clarity/FullStory) — which the agent is expected to read and use to drive recommendations, so untrusted public site content could indirectly inject instructions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata