battle
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly calls a /dogpile research skill (see the SKILL.md game loop "RESEARCH PHASE" and Task 14 / docs noting "Before each attack/defense, team can research strategies via dogpile" and config.DOGPILE_SKILL), which aggregates public third‑party providers (web, GitHub, YouTube, ArXiv, etc.), and those untrusted, user‑generated results are consumed and used to drive Red/Blue decisions (research → act → reflect), so they can materially influence tool use and next actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata