create-story

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In orchestrator.py the create() workflow passes outsider-authored free text from the thought argument into Phase 2/3 via run_skill("memory"... "--q", thought ...) / run_skill("ingest-movie"... "search", thought) / run_skill("ingest-book"... "search", thought) / dogpile_context(thought, ...), and the resulting external search/dogpile outputs are then embedded into the LLM draft prompt in story_phases.py (build_draft_prompt), creating an indirect prompt-injection ingestion path from attacker-controlled content discovered/returned by those tools.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:03 PM
Issues
1
Security Audit — snyk — create-story