stitch-loop

Warn

Audited by Snyk on Aug 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 이 스킬의 런타임은 project/next-prompt.md(바통 파일)의 YAML frontmatter/page와 본문 프롬프트를 먼저 읽고 그 자유형 텍스트를 stitch*:*generate_screen_from_text 프롬프트로 그대로 인지·사용하므로, 외부 사용자가 레포/큐에 해당 파일 내용을 간접적으로 주입할 수 있는 경우 간접 프롬프트 주입에 노출됩니다.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 25, 2026, 01:42 PM
Issues
1
Security Audit — snyk — stitch-loop