Warn
Audited by Snyk on Mar 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill calls the Gmail API (see skill-router.json baseUrl "https://gmail.googleapis.com" and SKILL.md actions "list-threads" / "get-thread") to fetch user email threads and message snippets, which are untrusted, user-generated content the agent reads and could use to drive replies or other actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata