resume
Warn
Audited by Snyk on Jun 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). At runtime the skill reads outsider-authored free text from the experiment’s persisted history files—specifically
.autoresearch/{domain}/{name}/results.tsvand.autoresearch/{domain}/{name}/program.md(viacat)—and injects that content into the agent’s LLM context when summarizing/reporting state.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata