ideas
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime workflow, the agent ingests outsider-authored free text from the user during
ideas capture(the interactive “What’s the idea?” free-text prompt orideas capture [text]) and then reads it later fromlog/ideas.mdforideas integrateclassification and approval.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill explicitly grants write/edit capabilities and includes a workflow that, after approval, "Make the edit" (including edits to "protected files" and infrastructure-related items like symlinks/permissions) and allows running limited bash, so it can be used to change the machine's state and potentially modify protected/system files.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata