create-boss

Warn

Audited by Snyk on May 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly asks for and ingests untrusted user/third‑party content (chats, meeting notes, pasted text, emails) as part of its core workflow—e.g., SKILL.md/README instructs users to provide source material and the repo includes parsers like tools/wechat_parser.py, tools/feishu_parser.py, tools/email_parser.py, and tools/generic_chat_parser.py—and those inputs are used to generate persona/judgment/management outputs that influence subsequent actions, so third‑party content could carry indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 11, 2026, 07:46 PM
Issues
1