retro
Warn
Audited by Snyk on Jul 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). SKILL.md:111-117 and Phase 1/3 describe reading session transcripts/logs and user messages, and retro_extract.py:132-250 shows it parses JSONL transcript records and extracts free-form
message.contentintouser_messages, which is then formatted into markdown (retro_extract.py:268-343) and would be fed into the LLM for retrospective analysis; these transcripts are outsider-authored content from prior agent/user interactions stored in.jsonlfiles.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata