debug
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
/debugPhase 0-2, the skill ingests the user-provided problem description (free text) and then the LLM uses it to plan and run probe commands (Bash/curl/grep/ls/trace), while also passing a “finding packet” to/seek-verdict; this means outsider/authored text is directly used at runtime rather than requiring the agent to first select a specific trusted item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata