paper-analyst

Warn

Audited by Snyk on Apr 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). Step 3 explicitly directs the agent to fetch ArXiv pages (via Exa search), visit paper URLs with WebFetch, and query Semantic Scholar—public third‑party sources whose untrusted content the agent will read and use to drive analyses and outputs, meeting the criteria for indirect prompt injection risk.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 24, 2026, 04:18 PM
Issues
1