audit-project

Warn

Audited by Snyk on Aug 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The runtime workflow reads only first-party, user-provided project files (pom.xml, application.properties, src/main/java) and uses the Quarkus Agents MCP for projectDir-based validation, but it does not ingest outsider-authored free text from external feeds/queues without first selecting specific items.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 11, 2026, 01:47 PM
Issues
1
Security Audit — snyk — audit-project