proj-work
Warn
Audited by Snyk on Jul 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md requires reading
spec.mdandtasks.mdfor an existing work item (EXECUTION mode), and those markdown files are authored outside the current runtime session by prior users (outsider text), which is then ingested into the agent’s LLM context to perform the “verify DONE claims” checks.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata