two-tier-extraction
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). This skill ingests a user-provided corpus item’s FULL CONTENT directly into the Step 1 triage call and Step 3 deep-read call, so outsider-authored free text can be posted into whatever archive/email/chat feed the pipeline processes.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata