fhir-ig-analyze

Warn

Audited by Snyk on Jul 31, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Source and runtime path: scripts/ig-stats.py run <input…> (via resolve_input then analyze) reads outsider-authored FHIR IG content from user-supplied local paths/git URLs/tgz packages—e.g., input/pagecontent/**/*.md, implementation-guides/**/*.page.md, input/fsh/**/*.fsh, qc/custom.rules.yaml, input/ignoreWarnings.txt—and processes those free-text files for reporting.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 31, 2026, 06:19 PM
Issues
1
Security Audit — snyk — fhir-ig-analyze