NYC

n8n-workflow-patterns

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs workflows and AI agents to fetch and consume open/public third‑party content (e.g., http_api_integration.md's HTTP Request examples, webhook_processing.md receiving arbitrary webhook payloads, and ai_agent_workflow.md where tools like HTTP Request, Wikipedia, Serper and "ANY node" are connected as ai_tool) and shows the AI Agent reading and interpreting those tool outputs, so untrusted user‑generated or web content can be ingested and influence the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:57 PM