Copilot Follow-up

Warn

Audited by Snyk on Mar 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflow explicitly pulls external enrichment and news (see SKILL.md Layer 2: "Company news: Check for recent funding, product launches, leadership changes... within the last 90 days") and the personalization guide also cites external sources like LinkedIn and industry reports (e.g., Bessemer) as signals the agent must read and incorporate, which are untrusted public third‑party content that can influence follow-up drafting and actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 3, 2026, 11:37 AM