skill-retrieval
Warn
Audited by Snyk on Sep 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow uses a pre-LLM-call hook (
_on_pre_llm_call) that ingests the user message (user_message), which contains untrusted free text submitted directly by an outside user.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata