pickup
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In SKILL.md (/pickup -- Session Pickup), the runtime workflow reads and parses a user-provided or user-selected local HANDOFF.md file and then reads listed Key Files from the “Key Files” table, so outsider-authored free text can be ingested via those local files.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata