juma-proposal

Warn

Audited by Snyk on Apr 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflow (SKILL.md — Process step 2 "Research client and industry") explicitly directs the agent to investigate the prospect's marketing presence, recent news, competitive positioning and industry trends from public third‑party sources, which the agent would need to fetch/interpret and could materially influence proposal decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 15, 2026, 11:18 AM
Issues
1