rterm-agentspan
Warn
Audited by Snyk on Jul 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In SKILL.md, outsider-authored free text is only passed into AgentSpan when the user explicitly provides
agentspan_run/agentspan_delegateinputs (e.g.,input/prompt/workflow.input.prompt), and the workflow itself is otherwise driven by first-party playbook/workflow definitions rather than ingesting an external feed.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata