code-changelog
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). 사용자가
CodeChangeLogger.log_file_creation()/log_file_modification()등에 전달한 임의 문자열(예: “이유”, “코드”, “old/new”)이reviews폴더의 MD 파일로 저장되고save_and_build()호출 시 HTML/HonKit 문서로 렌더링되어 브라우저에서 읽히는 흐름이므로, 외부 작성 텍스트가 직접 LLM이 아니라도 런타임 산출물에 포함됩니다.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata