delivery-review

Warn

Audited by Snyk on Jun 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). The required workflow reads the selected Kanban card and linked task item/source knowledge from <knowledge_dir>/planning/KANBAN.md and “linked task item,” which are outsider-authored free-form texts (e.g., issue/PR/wiki/discussion content) that can be ingested into the LLM context via those linked documents at runtime.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 14, 2026, 05:11 AM
Issues
1
Security Audit — snyk — delivery-review