pitfall-skill
Warn
Audited by Snyk on Jul 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Runtime path: the agent workflow writes the outsider-authored message text the user provides into
.pitfalls/ledger.yaml/.pitfalls/entries/*.mdvia thelogstep (e.g.,scripts/cli.js:77-159), and laterresolve/promotereads that free text back and emits it intoCLAUDE.md/AGENTS.md/*.mdcfor the LLM to use.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata