instinct-system
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow repeatedly ingests untrusted user-provided free text via the “Session-Start Loading” reading of MEMORY.md and the “Correction Capture Flow” where explicit user corrections are detected and then stored, meaning outsider-authored text can influence what the agent reads and uses.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata