notebooks

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's references explicitly instruct the agent to fetch and parse external release pages for container versions (references/container-versions.md) and to fetch remote OpenAPI specs and agent_card_url endpoints at runtime (references/manifest-schema.md / MCP server / Agent sections), which are untrusted third-party sources that can be parsed and converted into tools or influence deployment choices.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 03:26 AM