explore-deep
Warn
Audited by Snyk on Jul 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). In Step 2 the skill “Follow the sibling /explore skill exactly” and “Use Glob/Grep/Read aggressively”, which (in the required workflow) will read repository files not authored by the operating user (e.g., existing issues/wiki/discussion/codebase text from the consuming project) and include that free-text content in the LLM context during exploration.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata