weekly-digests

Warn

Audited by Snyk on Aug 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In SKILL.md Step 2, the workflow fetches the full claude-mem timeline from a local worker via curl http://localhost:${WORKER_PORT}/api/context/inject?project=PROJECT_NAME&full=true into .scratch/cm-timeline.md, and Step 3/5 then split-read and pass those contents verbatim into each subagent prompt as the weekly source file.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 3, 2026, 01:58 PM
Issues
1
Security Audit — snyk — weekly-digests