project-skill-protocol
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The outsider-controlled free text flows into the system at runtime by being loaded from the project’s overlay registry bodies (
docs/project-protocols/<slug>.md) which are applied as stored AI rules to govern the framework skill, i.e., the agent ingests user-authored overlay## Rulescontent when resolvingTarget/Scopeand then injecting the additive-only rules into the live workflow.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata