memory-sync-setup
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime workflow for the emitted
/memory-syncskill, the coordinator’s user-supplied “free-form prompt” becomes{FOCUS}and is then used while the skill reads and edits the project’s instruction-memory files across the whole swept surface, so outsider text can influence generation over LLM-ingested repo content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata