persona-seed
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In
persona-seed’s Phase 2/3 runtime path, outsider-provided free-textintent.query(from the user message that triggersrun-pipeline.js) is ingested and used to score against provider corpora viaprovider.search(intent), and the selected seed’s text fields are then fed into the mapper/generator; however, this free-text is the user’s own input (not outsider-authored content submitted to a monitored queue/feed by a third party).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata