loom

Warn

Audited by Snyk on May 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to "Web-search the topic, find 3-5 high-quality sources" (SKILL.md → Topic query) and requires Raw Capture entries with real URLs/raw_path and creation of Source Briefs and Synthesis Packs (references/schemas.md), so it ingests and reads public third‑party web content that directly drives research, synthesis, and subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 27, 2026, 02:51 AM
Issues
1
Security Audit — snyk — loom