team-adversarial-swarm
Warn
Audited by Snyk on Jul 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The required runtime workflow calls
wf-swarm-explore.js,wf-swarm-score.js,wf-swarm-converge.js, andwf-swarm-synthesize.js, and these agents ingestobjective,rubric,historyDigest, and especiallyant.evidence[].source/ant.evidence[].finding/candidate_solution.summarythat originate from outsider-authored free text (e.g., user-provided task intent and any evidence strings produced by other agents or imported artifacts), which is then embedded directly into the LLM prompts via template literals.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata