codenavi
Warn
Audited by Snyk on Feb 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Summon System and Knowledge Verification Chain explicitly require using web search (e.g., "Stack Overflow", "GitHub", "search the web") when MCPs lack answers, meaning the agent will fetch and read public, user-generated web content and use it to guide decisions and actions.
Audit Metadata