update-skill
Warn
Audited by Snyk on Jun 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). In
from-chat/from-dump/usagemodes, the skill scans and extracts “learnings” from recent conversation or pasted content, which can include outsider-authored free text (e.g., other participants’ chat messages or pasted transcripts) and then feeds those extracted learnings into the agent’s LLM context for proposing edits.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata