keyword-research
Warn
Audited by Snyk on Feb 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Mode 3 "Analyze" steps and the Mode 1 "Expand" instructions explicitly require deriving competitor keywords and inspecting SERP/features and proxy signals (e.g., "competitor-derived", "Google autocomplete", "People Also Ask", "forums (Reddit, Quora)"), which means the agent is expected to fetch and interpret open/public third-party content (competitor pages and public search/forum results) and use that information to drive prioritization and next actions.
Audit Metadata