no-code-pipelines
Warn
Audited by Snyk on Mar 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's reference/n8n-reference.md explicitly instructs the agent to fetch public n8n docs and community workflow pages (e.g., docs.n8n.io and n8n.io/workflows) via WebFetch/WebSearch to obtain node parameters and templates, meaning the agent will read open/public third-party (including user-generated community) content that can influence generated workflows.
Audit Metadata