model-roundtable
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill launches multiple outsider model seats (Codex/Gemini/Kimi/Opus) with a shared brief that includes the user’s original prompt; those seats’ outputs are read from
--output-fileasagent_messageand then fed back into the moderator’s LLM context for moderation, so outsider-authored free text (the seats’ JSON/text) becomes LLM context via the moderation/digest loop.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata