verify-openspec-docs

Warn

Audited by Snyk on Aug 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In verify-openspec-docs the runtime workflow ingests and reviews outsider-provided free text only insofar as the user supplies a “page or section”/“changed claims” to check, which the reviewer subagent then reads from the docs tree and re-runs/validates against commands and repo files.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 09:30 PM
Issues
1
Security Audit — snyk — verify-openspec-docs