workflows

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and converts remote third-party content at runtime — e.g., remote OpenAPI specs for MCP servers ("MCP Server (OpenAPI)" with spec.type: remote and url) and hosted A2A agent cards/agent_card_url ("Agent" section, hosted-a2a-agent) — which are untrusted external URLs that are parsed into MCP tools or agent behavior and can directly change tool capabilities and actions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 03:26 AM