tech-spec

Warn

Audited by Snyk on Aug 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In scripts/generate-tech-specs.mjs, the generator reads repository test source files from the configured docs/project-config.json techSpecScan.sourceRoot/extensions (e.g., collectTraitEntries → parseTraitEntries → fs.readFile(filePath,'utf8')) and extracts free-text code/annotation content, which can be outsider-authored if an attacker can submit/poison tests in the repo.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 08:23 PM
Issues
1
Security Audit — snyk — tech-spec