company-brain
Warn
Audited by Snyk on Aug 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
querymode, the skill ingests free-text from all first-party vault files undermeetings/,people/,companies/, etc. (which are populated from outsider-authored sources like Slack, email, sales call transcripts, or support tickets via auto-sync), so an outsider can inject poison by submitting content that gets captured into the vault and later compiled/queried without additional selection constraints beyond those files.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata