cap-llm-plugin
Warn
Audited by Snyk on Jul 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow ingests free-text from the caller via CAP service events (e.g.,
req.data.question/context) and directly includes it in the prompt sent to the LLM, enabling outsider-authored prompt injection through user input.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata