codenavi

Warn

Audited by Snyk on Feb 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's Summon System and Knowledge Verification Chain explicitly require using web search (e.g., "Stack Overflow", "GitHub", "search the web") when MCPs lack answers, meaning the agent will fetch and read public, user-generated web content and use it to guide decisions and actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 09:30 AM