weekly-digests
Warn
Audited by Snyk on Aug 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In SKILL.md Step 2, the workflow fetches the full claude-mem timeline from a local worker via
curl http://localhost:${WORKER_PORT}/api/context/inject?project=PROJECT_NAME&full=trueinto.scratch/cm-timeline.md, and Step 3/5 then split-read and pass those contents verbatim into each subagent prompt as the weekly source file.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata