herdr
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Yes—this workflow can call
herdr pane read/herdr wait output, which reads another pane’s terminal text (free-form output) via herdr’s local socket and injects it into the agent’s LLM context as prose.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata