kakao-bar-nearby

Warn

Audited by Snyk on Mar 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly queries Kakao Map public endpoints (e.g., place panel3 JSON at https://place-api.map.kakao.com/places/panel3/ and place detail pages at https://place.map.kakao.com/), ingests and normalizes third‑party place/menu/phone/operating-status data as part of its workflow and uses that content to decide which venues to show and in what order, so untrusted user-generated/open web content could influence agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 30, 2026, 04:07 PM
Issues
1