docs

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill instructs the agent to fetch and summarize live TrueFoundry documentation pages (e.g., https://truefoundry.com/docs/..., via curl or WebFetch) and also references other remote sources (GitHub/NGC release pages, HuggingFace artifacts, remote OpenAPI specs, and agent_card_url endpoints) which the agent is required to read and which could materially influence deployments or tool behavior, exposing it to untrusted public web content that could enable indirect prompt injection.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 03:25 AM