tooluniverse-cancer-variant-interpretation
Warn
Audited by Snyk on Mar 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly instructs the agent to fetch and interpret content from public third-party sources—e.g., CIViC, PubMed, ClinicalTrials.gov, cBioPortal, OpenTargets, FDA, DrugBank, ChEMBL, Reactome, and GTEx—and to use that content to drive clinical recommendations and tool calls, so externally authored web/database content could materially influence the agent's decisions and enable indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata