maestro-amend
Warn
Audited by Snyk on Jul 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.72). Outsider free text can enter the LLM context via runtime ingestion of user-supplied directories/files for
--from-verify/--from-review/--from-issuesand via--scanreading.workflow/artifacts (e.g.,issues.jsonl,review.json, execution summaries) that may contain third-party-authored text; the skill then parses/extracts those contents into signals for diagnosis and overlay drafting.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata