teach
Warn
Audited by Snyk on Jul 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md instructs the agent to read workspace files like
./reference/*.html,MISSION.md,RESOURCES.md, and./learning-records/*.md—which are free-text documents sourced from files the user/outer system provides—so at runtime the LLM can ingest outsider-authored content (including any HTML/markdown the operating user didn’t write themselves).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata