tooluniverse-adverse-event-detection
Warn
Audited by Snyk on Mar 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly ingests and acts on open/public third-party content — notably FAERS adverse event reports (user-submitted spontaneous reports) and literature/preprints from PubMed/OpenAlex/EuropePMC as shown throughout SKILL.md (Phases 1, 2, 7), and it uses that content to calculate disproportionality metrics and a Safety Signal Score that drive recommendations, creating a clear avenue for indirect prompt-injection via untrusted data.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata