ollama-launch
Warn
Audited by Snyk on Apr 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs pulling models from the public Ollama registry (e.g., "ollama pull qwen2:7b") and the skill runs local Ollama for RLM distillation and embeddings (Learning Loop Seal Phase / RLM Factory), so the agent fetches and consumes third‑party model outputs that can materially influence decisions and tool use.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata