gtm-workspace

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The gtm-workspace skill’s create/import update/doctor flows ingest outsider-authored free text from user-supplied links, files, and folders via the runtime “Research” steps (e.g., Create step 4/5 and Import step 2-8), which are then read by the LLM to draft and preview durable workspace content.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:29 PM
Issues
1
Security Audit — snyk — gtm-workspace