kernel-write-transcript
Warn
Audited by Snyk on Jul 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The required workflow is to “Read the entire transcript” and transform it into a document using the referenced contract, meaning any transcript content (if authored by someone other than the operating user) would be fed as free-form text into the agent’s LLM context; the skill spec itself doesn’t constrain transcript authorship.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata