sop-builder

Warn

Audited by Snyk on Aug 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The runtime workflow ingests outsider-authored free text because it captures the owner’s spoken/uploaded process (“spill.md” written verbatim) and then feeds that content (especially Business Context and rendered flow) into the Stage 5 critique subagent via {{BUSINESS_CONTEXT}}, {{OBJECTIVE}}, and {{FLOW}} without filtering for prompt-injection text.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 23, 2026, 12:40 PM
Issues
1
Security Audit — snyk — sop-builder