battle

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly calls a /dogpile research skill (see the SKILL.md game loop "RESEARCH PHASE" and Task 14 / docs noting "Before each attack/defense, team can research strategies via dogpile" and config.DOGPILE_SKILL), which aggregates public third‑party providers (web, GitHub, YouTube, ArXiv, etc.), and those untrusted, user‑generated results are consumed and used to drive Red/Blue decisions (research → act → reflect), so they can materially influence tool use and next actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:34 AM
Issues
1
Security Audit — snyk — battle