NYC

n8n-expression-syntax

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's examples (EXAMPLES.md, e.g. "Template from Real Workflow" and several webhook examples) show Webhook nodes ingesting user-provided body data and HTTP Request nodes calling public APIs such as https://nominatim.openstreetmap.org and api.weather.gov, so the agent is expected to read and interpret untrusted third-party/user-generated content at runtime.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 09:06 PM