skill-opt-lite

Warn

Audited by Snyk on Aug 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The training loop ingests outsider-authored free text via the user-supplied tasks/train.json and tasks/valid.json fields (especially instruction/expected_outcome/test_command) at runtime in both ROLLOUT and GATE validation, before any specific item selection in the external text source is enforced.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 16, 2026, 07:07 AM
Issues
1
Security Audit — snyk — skill-opt-lite