lifeos-memory
Warn
Audited by Snyk on Feb 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly spawns agents for "research or data gathering" (Agent-First Rule) and includes a "Research Task" example that directs the agent to find SAT dates using public sources (e.g., "Use official College Board data only"), which clearly requires fetching and interpreting open/public third‑party content as part of the workflow (SKILL.md, "Example 2: Research Task" and "Spawn an agent" sections).
Audit Metadata