30x-seo-content-brief
Warn
Audited by Snyk on Mar 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow (Step 1: "SERP Scraping") explicitly scrapes the Top 10 public SERP results—fetching page content (H1/H2/H3, meta, full text) from arbitrary websites—which the agent then analyzes to drive topic extraction, gap analysis, and brief generation, exposing it to untrusted third‑party content that could inject instructions.
Audit Metadata