testsprite-ai-testing-cli
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The required runtime workflow “Handle Failures (Agent Entry Point)” uses
testsprite test failure get ... --out ...to download a failure bundle containing readable text likefailure.jsonandtest-source.tsfrom TestSprite’s service; that content is not authored by the operating user and can include arbitrary free text (e.g., error messages/root-cause hypotheses) that the agent may ingest into its LLM context.
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata