voice-extract

Warn

Audited by Snyk on Apr 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflow ingests and analyzes user-provided writing samples from the Sample Intake (directory mode copying files from a user-specified folder and interactive paste) and then runs those untrusted/user-generated samples through the SICO extraction (Pass 1/Pass 2) to produce registers that drive later behavior, so public/social-source content (e.g., Reddit/slack examples mentioned) is explicitly consumed and can materially influence agent actions (SKILL.md Step 1 + modules/sample-intake.md and modules/sico-extraction.md).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 13, 2026, 11:27 PM
Issues
1