session-feedback
Warn
Audited by Snyk on Jul 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). In Write mode, the skill walks the live conversation and emits a Markdown feedback file containing extracted outsider-authored free text (i.e., the operating user’s interlocutor/user-turns), which then becomes readable LLM context in Recall mode when
feedback_*.mditems are surfaced and listed at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata