Copilot Follow-up
Warn
Audited by Snyk on Mar 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow explicitly pulls external enrichment and news (see SKILL.md Layer 2: "Company news: Check for recent funding, product launches, leadership changes... within the last 90 days") and the personalization guide also cites external sources like LinkedIn and industry reports (e.g., Bessemer) as signals the agent must read and incorporate, which are untrusted public third‑party content that can influence follow-up drafting and actions.
Audit Metadata