skill-lab
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's required workflow (SKILL.md Quick Start and run.sh/composer.py) explicitly shows composing and executing pipelines for tasks like "continuously monitor arxiv" and "extract PDF and store to memory", and the bond_harvest/warm_pond pipeline runs and harvests results from executed skill chains (including extractors) which will fetch and ingest public web content (e.g., arXiv papers/PDFs) that the agent reads and whose outcomes (traces/labels/attractors) materially influence model training and pipeline selection—so untrusted third‑party content is clearly consumed and can affect next actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata