projects
Warn
Audited by Snyk on Apr 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Phase 1 workflow explicitly instructs the agent to ingest external content—e.g., "Google Doc dump: Extract structure" and "check the codebase, existing reports, and web before accepting the gap" with fallback to "WebSearch for web context" and dispatching /research or /worldmodel—so it fetches and reads untrusted public/user-generated web content that will be interpreted and used to drive decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata