commerce-integrated-strategy
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md의 워크플로우는
commerce-morning-brief/대시보드 내보내기·스크린샷, 채널 관리자/광고 보고서 내보내기 파일(또는 사용자가 첨부한 내보내기 파일·스크린샷)을 LLM이 분석하고, 이때 텍스트가 무작위 사용자 제공(외부 산출물 첨부 포함)일 수 있어 간접 프롬프트 인젝션이 매크로 입력 경로에 노출됩니다.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata