ingest

Warn

Audited by Snyk on Jul 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). SKILL.md Phase 2/3 reads report files from research_dirs (e.g., find "$rd" ... "*-daily-research.md" ...) and then feeds the full report text into the ingestion-analyst sub-agent tool call (user prompt includes “The full text of the report (read the file)”), so if those report files are outsider-authored, their free text reaches the LLM context.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 15, 2026, 03:21 AM
Issues
1
Security Audit — snyk — ingest