wren-enrich-context
Warn
Audited by Snyk on May 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill reads arbitrary free-text from
raw/at runtime (“Read every file underraw/”), and that content can be authored by outsiders (e.g., downloaded PDFs/handbooks or pasted excerpts), which the agent then ingests into the LLM context for gap detection and inference.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata