distill-skill
Warn
Audited by Snyk on Jul 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider-authored free text from the recorded CC session (e.g., other participants’ messages) is appended into
trace.jsonlasfriction/user_intentand then fed to the LLM via the required/edit-toolhandoff usingdraft.yamlandanti-patterns.md(runtime prompt construction includes that content).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata