n8n
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly shows runtime ingestion of untrusted third-party content via HTTP Request/code node examples (e.g., fetch and this.helpers.request to arbitrary APIs), Webhook trigger patterns that accept external payloads, Document Loaders and RAG workflows that pull text for vector stores, and references to public community resources (community.n8n.io / public templates), so the agent is expected to read and act on open/public user-generated content.
Audit Metadata