voice
Warn
Audited by Snyk on May 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Multi-Channel Synthesis workflow (references/multi-channel-synthesis.md
- Source Inventory) explicitly calls for ingesting public, user-generated channels (App Store reviews, G2/Capterra, social media via API/scraping) and uses those texts to drive analysis, prioritization, and routing, which exposes the agent to untrusted third-party content that could carry indirect prompt-injection instructions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata