signal
Warn
Audited by Snyk on Mar 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill ingests and uses incoming Signal messages and group history (e.g., "Group history context uses channels.signal.historyLimit" and DM/group handling via signal-cli) — untrusted, user-generated third‑party content — as runtime context that can influence replies, reactions, and downstream actions described in the workflow (Group Chat Safeguards, Sending Messages, Reactions), so it can enable indirect prompt injection.
Audit Metadata