roadrunner-build-scenario-from-osc
Warn
Audited by Snyk on Aug 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill ingests outsider-authored free text at runtime only from the user-supplied
.xoscfile (including referenced catalog.xmlfiles and the referenced.xodrfor position translation), parses/evaluates${...}expressions, and extracts construct properties and parameters from those XML strings before producing the scenario description.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata