gtm-onboarding
Warn
Audited by Snyk on Jun 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). Outsider free text is ingested because the skill uses
AskUserQuestionto collect user-provided answers (which are not guaranteed to be authored by the operating user) and then writes/summarizes that content intoprojects/<project>/gtm-context.md, which later GTM skills read into their LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata