travel-dossier
Warn
Audited by Snyk on Jul 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). High:
SKILL.md:12-14requires collecting user-supplied truth files (it explicitly asks for PDFs/emails and optional research), and that extracted text is then ingested into the agent’s LLM context for extraction/alignment inSKILL.md:19-22; since those documents can be outsider-authored (e.g., travel agency itineraries, tickets/confirmations, and optional research from third parties), there is a runtime path for outsider free-text to reach the LLM (indirect prompt injection risk).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata