create-boss
Warn
Audited by Snyk on May 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly asks for and ingests untrusted user/third‑party content (chats, meeting notes, pasted text, emails) as part of its core workflow—e.g., SKILL.md/README instructs users to provide source material and the repo includes parsers like tools/wechat_parser.py, tools/feishu_parser.py, tools/email_parser.py, and tools/generic_chat_parser.py—and those inputs are used to generate persona/judgment/management outputs that influence subsequent actions, so third‑party content could carry indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata