consensus-plan-review
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
references/command.md, the workflow takes$ARGUMENTS/user task verbatim intoprompt.mdand then feeds that free text into external model CLIs viapi/OpenRouter,agy, andqwencommands (e.g.,$(cat "$SESSION_DIR/prompt.md")), so an outsider can submit poison free text through the invocation input that is ingested by the models.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata