prompt-lab

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's prompts and workflow explicitly state it ingests "knowledge excerpts from URLs" (see .pi/skills/prompt-lab/prompts/12_qra_TACTIC_CONTROL_PROMPT.txt and SKILL.md's eval-qra/test-sparta descriptions), and that source text from those URLs is read and used to generate grounded QRA outputs and drive self-correction, so the agent clearly consumes untrusted public web content that can influence its actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:38 AM
Issues
1
Security Audit — snyk — prompt-lab