eve-read-eve-docs
Warn
Audited by Snyk on May 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly ingests and routes inbound user-generated messages (including public social providers like Nostr and Slack) — see references/agents-teams.md which describes routing inbound Slack/Nostr messages, injecting coordination thread messages and regenerating .eve/coordination-inbox.md for jobs — so external, untrusted third‑party content is read and used to drive dispatch and agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata