code-changelog

Warn

Audited by Snyk on Aug 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). 사용자가 CodeChangeLogger.log_file_creation()/log_file_modification() 등에 전달한 임의 문자열(예: “이유”, “코드”, “old/new”)이 reviews 폴더의 MD 파일로 저장되고 save_and_build() 호출 시 HTML/HonKit 문서로 렌더링되어 브라우저에서 읽히는 흐름이므로, 외부 작성 텍스트가 직접 LLM이 아니라도 런타임 산출물에 포함됩니다.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 12:52 PM
Issues
1
Security Audit — snyk — code-changelog