using-gc
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). SKILL runtime path reads GC run/session/bead/pane state via the operator/operator-orchestrator observability loop (
$API/runs/*,gc bd ... --json, andtmux capture-pane), but the text ingested at runtime is GC state/prose from the caller-provided intent bead and session artifacts rather than an externally submitted outsider-authored feed/queue that the workflow monitors without selecting a specific item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata