ws-workflow-engine-bridge
Warn
Audited by Snyk on Apr 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly imports and executes Author Workflow Engine JSON prompt sequences ("Import: Load AWE JSON into AuthorClaw's automation engine" and the
import workflow from [path]command), meaning externally authored/untrusted prompt content is ingested and run as steps that can change routing, model selection, and subsequent actions, so it can enable indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata