designing-genai-patterns

Warn

Audited by Snyk on Mar 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs ingesting and indexing open/public content for RAG and agent workflows—see INSTRUCTIONS.md RAG sections and references/RAG-DATA-LOADING.md and references/OPS-DATA-ENGINEERING.md (web crawlers, CommonCrawl, public websites, PDFs, etc.)—and agents are expected to read and act on those untrusted documents (e.g., references/AGENTIC-SYSTEMS.md Tool Calling warns of prompt-injection), so third-party content can materially influence tool use and decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 11:13 PM
Issues
1