retro

Warn

Audited by Snyk on Jul 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). SKILL.md:111-117 and Phase 1/3 describe reading session transcripts/logs and user messages, and retro_extract.py:132-250 shows it parses JSONL transcript records and extracts free-form message.content into user_messages, which is then formatted into markdown (retro_extract.py:268-343) and would be fed into the LLM for retrospective analysis; these transcripts are outsider-authored content from prior agent/user interactions stored in .jsonl files.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 13, 2026, 08:16 AM
Issues
1
Security Audit — snyk — retro