pick-theme
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider-authored free text is read at runtime from
theme.mdfiles andmanifest.jsonfiles located under$COGNI_WORKSPACE_ROOT/themes/(and via auto-discovered workspace roots under~/*/~/Library/CloudStorage/*/*/), which is then parsed into JSON fields (name,description,primary/accent/background, andmanifest_error) and fed into the LLM via the “Present discovered themes via AskUserQuestion” workflow.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata