multi-group-architecture

Warn

Audited by Snyk on Feb 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill directly ingests and acts on untrusted user-generated LINE messages (see the handle_message MessageEvent which reads event.message.text and parses '@' commands to update schedules/members), so third-party content from group users can materially influence the agent's actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 21, 2026, 10:21 AM