skill-system-insight

Warn

Audited by Snyk on Jun 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). The runtime LLM context is fed by the stored facet YAMLs (category insight-facet) and soul-state YAML pulled from Postgres via get_recent_facets() / get_soul_state() into prompts/evolution-planning.md and prompts/recipe-evolution.md, and those facet YAMLs are derived from the full session transcript which can include outsider-authored free text (e.g., other participants’ messages in the transcript) that the agent then re-ingests as evidence.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 02:20 PM
Issues
1
Security Audit — snyk — skill-system-insight