agently-prompt-config-files

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's loaders explicitly read prompt content from files or raw text and even list "prompt text fetched from a remote config service" as an intended use (references/loading-mappings-and-key-paths.md), and that loaded prompt config (including .alias) is executed into agent/request prompt state so untrusted, public config could materially change agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 05:51 PM
Issues
1