worker
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md’s runtime workflow reads outsider-authored free text from the user’s/team’s state directory at
<team_state_root>/team/<teamName>/workers/<workerName>/inbox.md(inbox instructions) and mailbox messages at<team_state_root>/team/<teamName>/mailbox/<workerName>.json, then uses those contents to decide and execute tasks.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata