manage-personas

Warn

Audited by Snyk on Jul 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). At runtime, the resolver reads outsider-authored free text from persona bundle files (e.g., skills/{skill}/SKILL.md frontmatter) via _read_persona_frontmatter()_leading_frontmatter()/_parse_yaml_list(), and then returns it as skills[] in the TOON output that the executor/agent includes in the LLM context; this is indirect prompt-injection exposure from public/third-party persona content.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 11, 2026, 07:12 AM
Issues
1
Security Audit — snyk — manage-personas