qa-observability
Warn
Audited by Snyk on Apr 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md "Fact-Checking" step explicitly instructs the agent to "Use web search/web fetch to verify current external facts" and to validate vendor/docs (i.e., fetch arbitrary public web pages / primary sources), so the agent will ingest untrusted third‑party web content that can materially influence decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata