participation-warmup-planner
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s required runtime workflow ingests community “public surfaces” via connectors (e.g.,
scripts/connectors/discourse.py,hn.py,bluesky.py/fediverse.py) and also accepts “User-provided pasted rules/exports,” so outsider-authored free text can be read before any specific item selection by the agent (e.g., the fetched forum/threads/feeds that those connectors return).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata