literature-review

Warn

Audited by Snyk on Apr 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches and ingests open/public literature (e.g., search_literature against PubMed, get_fulltext(pmcid)/download PDF, and ingest_documents(file_paths)) and requires the agent/subagents to read and act on those fulltexts as part of its workflow (see the SKILL.md steps for fulltext ingestion and runSubagent prompt), so third-party webpage/PDF content can directly influence analysis and subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 14, 2026, 01:03 PM
Issues
1