audit-project
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The runtime workflow reads only first-party, user-provided project files (pom.xml, application.properties, src/main/java) and uses the Quarkus Agents MCP for projectDir-based validation, but it does not ingest outsider-authored free text from external feeds/queues without first selecting specific items.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata