knowledge-finalize
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.72). Outsider free text can enter the LLM context via the
portal-narratoragent (Step 10.5 sub-step 3.5): it builds aportal-bundle.txtby readingwiki/index.md(which may include human-authored lead-ins/bullets) and then dispatchesTask(portal-narrator, BUNDLE_PATH=...), so the agent receives that page text as prompt/context at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata