agent-access-control

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill explicitly ingests and processes untrusted user-generated messages from public messaging platforms (WhatsApp/Telegram/Discord/Signal) as shown in SKILL.md "Message Handling Flow" where it extracts sender IDs, stores the message "firstMessage" in pendingApprovals, and notifies the owner with the first 100 chars — content that can influence approval decisions and subsequent agent privileges.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 09:38 AM