qmd

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md describes an MCP/HTTP runtime workflow where the agent sends user-authored search queries (e.g., via the query tool or POST /query body) into QMD, which can then retrieve matching markdown content from the configured local collections; while that retrieved markdown is “inside” the tenant, the workflow ingests free text from outsiders before selecting any specific item.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 11:04 PM
Issues
1
Security Audit — snyk — qmd