chief-of-staff

Warn

Audited by Snyk on Jul 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.78). This skill reads and summarizes outsider-authored free text from Gmail email bodies/headers and WhatsApp messages fetched at runtime (SKILL.md “Email triage” via gog gmail search and “WhatsApp (last 24h)” via ssh mini + sqlite3), then includes that content in the prompt context for the LLM to assemble the briefing.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 26, 2026, 10:23 PM
Issues
1
Security Audit — snyk — chief-of-staff