executing-plans
Warn
Audited by Snyk on May 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md freshness check requires hitting real external sources ("For each external API/file the plan references, hit the real source — live curl, file read, version check") which causes the agent to fetch and interpret live third‑party (e.g., HTTP/SDK) content that can change decisions in the execution workflow.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata