project-skill-protocol

Warn

Audited by Snyk on Aug 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The outsider-controlled free text flows into the system at runtime by being loaded from the project’s overlay registry bodies (docs/project-protocols/<slug>.md) which are applied as stored AI rules to govern the framework skill, i.e., the agent ingests user-authored overlay ## Rules content when resolving Target/Scope and then injecting the additive-only rules into the live workflow.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 08:23 PM
Issues
1
Security Audit — snyk — project-skill-protocol