gaps-generate
Warn
Audited by Snyk on Jul 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The required workflow reads the user-supplied
ga-process.yml(a free-form YAML file provided at runtime) and feeds its contents into the generator/validator scripts, which then produce LLM-readable text/artifacts; this is outsider-authored content if the operating user did not author that process file.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata