deity-agent-builder

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly includes WebSearch and WebFetch built-in tools (see reference/tools-reference.md, SKILL.md Step 4 and the templates that register / ) which fetch public URLs and whose outputs are consumed by agents (tools registered in the LLM loop, Result/Observe/Validate logic and workflow items), so untrusted third‑party page content can be read and materially influence LLM decisions and subsequent tool use.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 08:37 AM