gtm

Warn

Audited by Snyk on Jun 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). The required runtime workflow ingests outsider-authored free text from upstream artifacts the user did not author (e.g., DESIGN.md from brand-workshop, validation-canvas.md from validation-canvas, and deck.html from pitch-deck), which GTM reads and places into the agent’s LLM context during Phase 0/1 playbook construction.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly includes autonomous spending of advertising budgets. In P3 (autonomous-with-escalation) the document states "spend ad budget up to configured caps" and describes helper functions like check_budget(category, cost), budget thresholds, and escalation/blocking logic for budget hits. Those are specific, built-in execution controls to move ad spend (financial operations), not merely generic browsing or logging. While it doesn't mention Stripe/PayPal/crypto/banking APIs by name, the explicit capability to spend ad budget (with enforcement and automation) falls under "Direct Financial Execution" per the managing-ad-spend criterion.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 07:11 AM
Issues
2
Security Audit — snyk — gtm