scrapesocial-facebook

Warn

Audited by Snyk on Mar 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to fetch and ingest public, user-generated Facebook content (pages, posts, comments, groups, and ad library data) via commands like "facebook profiles posts", "facebook comments", "facebook groups posts", and "facebook ads search" (see the Minimal examples and workflows), so untrusted third‑party text is read and used to drive analysis and follow-up actions, enabling indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 04:46 PM
Issues
1