jtbd-interview-analyzer

Warn

Audited by Snyk on Jun 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). The required workflow ingests “raw JTBD interview transcripts” provided by the operating user, but the skill also explicitly extracts quotes from those transcripts at runtime; if those transcripts include outsider-authored text (e.g., other people’s interview responses), that free-form prose is fed into the agent’s LLM context via the transcript input.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 30, 2026, 08:26 PM
Issues
1
Security Audit — snyk — jtbd-interview-analyzer