harness-engineering-orchestrator
Warn
Audited by Snyk on Mar 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's Market Research and Frontend Designer agents explicitly instruct the agent to search and ingest public web content and reference websites (see agents/market-research.md "Search" strategy and agents/frontend-designer.md "If the user provided a reference App / website, first research that product's design patterns"), which are untrusted third‑party sources and whose findings are used to influence tech-stack, PRD, and design decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata