exploring-scouts
Warn
Audited by Snyk on Jul 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
SKILL.mdthe required runtime workflow for this “exploring signals scouts” skill reads and renders free-text fields that are derived from scout session transcripts and reports (e.g.,scout-runs-retrieve/tasks-runs-session-logs-retrievesummaries and tool inputs/agent narration, andinbox-reports-retrievereport contents viaemitted_report_ids/edited_report_ids), where those transcripts and report bodies can be influenced by outsider-authored data present in the monitored project signals.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata