pia-generation
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly requires the agent to "research the currently operative mandatory-assessment triggers" including web searches (
"search the web — results will be tagged [web search — verify]") and to ingest user-provided materials (e.g., "PRD: [Drive link]" / "Can pull from PRD if provided"), so the agent will fetch and interpret open/public or user-supplied third‑party content that can materially change PIA decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata