octocode-awareness
Warn
Audited by Snyk on Aug 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The runtime workflow centers on local
attend/SQLite state and deterministic CLI operations, and the only outsider text path described is transient host-prompt delivery (hook bytes capped) that is not treated as a monitored external feed/source read without an explicit join/selection step.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata