skill-lab

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's required workflow (SKILL.md Quick Start and run.sh/composer.py) explicitly shows composing and executing pipelines for tasks like "continuously monitor arxiv" and "extract PDF and store to memory", and the bond_harvest/warm_pond pipeline runs and harvests results from executed skill chains (including extractors) which will fetch and ingest public web content (e.g., arXiv papers/PDFs) that the agent reads and whose outcomes (traces/labels/attractors) materially influence model training and pipeline selection—so untrusted third‑party content is clearly consumed and can affect next actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:39 AM
Issues
1
Security Audit — snyk — skill-lab