persona-seed

Warn

Audited by Snyk on Aug 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). In persona-seed’s Phase 2/3 runtime path, outsider-provided free-text intent.query (from the user message that triggers run-pipeline.js) is ingested and used to score against provider corpora via provider.search(intent), and the selected seed’s text fields are then fed into the mapper/generator; however, this free-text is the user’s own input (not outsider-authored content submitted to a monitored queue/feed by a third party).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 13, 2026, 01:55 AM
Issues
1
Security Audit — snyk — persona-seed