gtm
Warn
Audited by Snyk on Jun 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime workflow ingests outsider-authored free text from upstream artifacts the user did not author (e.g.,
DESIGN.mdfrombrand-workshop,validation-canvas.mdfromvalidation-canvas, anddeck.htmlfrompitch-deck), which GTM reads and places into the agent’s LLM context during Phase 0/1 playbook construction.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes autonomous spending of advertising budgets. In P3 (autonomous-with-escalation) the document states "spend ad budget up to configured caps" and describes helper functions like check_budget(category, cost), budget thresholds, and escalation/blocking logic for budget hits. Those are specific, built-in execution controls to move ad spend (financial operations), not merely generic browsing or logging. While it doesn't mention Stripe/PayPal/crypto/banking APIs by name, the explicit capability to spend ad budget (with enforcement and automation) falls under "Direct Financial Execution" per the managing-ad-spend criterion.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata