apex-27

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The SKILL.md explicitly instructs the agent to run Membrane actions and to use "membrane request CONNECTION_ID /path/to/endpoint" (the "Proxy requests" and "Running actions" sections) which fetches data from the external Apex 27 API (third-party, potentially user-generated/untrusted content) and the agent is expected to read and act on those responses, so returned content could influence subsequent tool use.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 08:58 AM