ceratops-contract-review
Warn
Audited by Snyk on Jun 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.72). The required workflow refreshes evidence by “Check current official GitHub docs … and at most 2-3 current public third-party GitHub reference repositories” and “Use local files, gh, GitHub API, … and registry endpoints as the first-pass evidence,” which can ingest outsider-authored free text from public web pages / third-party repos into the LLM context during runtime evidence gathering.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata