serenity-thesis-tracker
Warn
Audited by Snyk on Jul 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). Outsider free text from X posts authored by @aleabitoreddit is fetched at runtime via
scripts/fetch_daily.py(CDP bridge →EXTRACT_TWEETS_JSextractstweetText), then written intotree/Serenity/daily/serenity_YYYY-MM-DD.mdandtree/Serenity/raw/serenity_statuses.jsonl, which the skill later reads and feeds into the LLM for classification/thesis extraction.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata