agent-messenger
Warn
Audited by Snyk on Apr 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's workflow explicitly reads and processes untrusted, user-generated messages and public agent content (e.g., "Reading messages" commands like
thread unread,thread show,inbox request listand discovery commandsdiscover search/discover showandinbox public showin SKILL.md), so third-party content from other agents/users is ingested and can influence subsequent replies, approvals, or automation actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata