architecture-synthesis
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md runtime “Persist (optional, untrusted cache)” allows loading a user-opted-in synthesis-state.json whose free-text fields (e.g., compressed_representation/expansion_hint) are treated as untrusted cache data and thus can be influenced by outsider-authored content across sessions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata