prompt-lab
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's prompts and workflow explicitly state it ingests "knowledge excerpts from URLs" (see .pi/skills/prompt-lab/prompts/12_qra_TACTIC_CONTROL_PROMPT.txt and SKILL.md's eval-qra/test-sparta descriptions), and that source text from those URLs is read and used to generate grounded QRA outputs and drive self-correction, so the agent clearly consumes untrusted public web content that can influence its actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata