verify-openspec-docs
Warn
Audited by Snyk on Aug 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
verify-openspec-docsthe runtime workflow ingests and reviews outsider-provided free text only insofar as the user supplies a “page or section”/“changed claims” to check, which the reviewer subagent then reads from the docs tree and re-runs/validates against commands and repo files.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata