NYC

manus

Warn

Audited by Snyk on Feb 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly performs web browsing and "gathers and combines information from multiple websites" (SKILL.md) and accepts arbitrary URL attachments/connectors ("File Attachments" and "connectors"/"createShareableLink" in SKILL.md and references/api.md), so it fetches untrusted public content that the agent reads and uses to drive its research and actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 19, 2026, 05:26 PM