consensus-plan-review

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In references/command.md, the workflow takes $ARGUMENTS/user task verbatim into prompt.md and then feeds that free text into external model CLIs via pi/OpenRouter, agy, and qwen commands (e.g., $(cat "$SESSION_DIR/prompt.md")), so an outsider can submit poison free text through the invocation input that is ingested by the models.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 04:48 AM
Issues
1
Security Audit — snyk — consensus-plan-review