list-growth-designer
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill “List Growth Designer” ingests user-provided growth goal/audience/jurisdiction and “current signup”/growth history exports or pasted records, which are treated as untrusted free text at runtime (e.g., CSV/report-style inputs) and the workflow directly consumes that text to produce the plan and consent-flow spec.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata