tech-spec
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/generate-tech-specs.mjs, the generator reads repository test source files from the configureddocs/project-config.jsontechSpecScan.sourceRoot/extensions (e.g.,collectTraitEntries→parseTraitEntries→fs.readFile(filePath,'utf8')) and extracts free-text code/annotation content, which can be outsider-authored if an attacker can submit/poison tests in the repo.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata