evaluate-ghostwriter
Warn
Audited by Snyk on Jul 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The runtime path
scripts/run-eval.tsreads outsider-authored case-data JSONL (fromevals/cases.jsonl/--cases), converts it into a “Case data” prompt string viabuildCommonPrompt()/buildCandidatePrompt(), and feeds that free text into the model invocation; this is an outsider free-text source (cases are not created by the user per SKILL.md).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata