portfolio-consolidate
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md’s required workflow reads outsider-authored free text from
research/.metadata/scan-output.jsonand its sibling markdown report (including parsed[Status: X]tags) produced by priorportfolio-scanruns for other peer companies, so at runtime that scraped/report text becomes LLM-readable context; there’s also user-supplied scope selection viaAskUserQuestionbut that’s user-authored.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata