careful
Warn
Audited by Snyk on Aug 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime path
bin/check-careful.shreads JSON tool input fromstdinand parses the user/outsider-provided"command"field (INPUT=$(cat)andCMD=...), making the agent’s required workflow dependent on outsider free text (the command string) before deciding whether to warn.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata