autoresearch
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In
autoresearch.mdtheGoal/Scope/Symptom/Taskis user-provided free text, and the workflow can run looping subcommands that “read results TSV” and “read git history as memory” at runtime, but it does not ingest any outsider-authored content from external queues/feeds/issue bodies without the user first selecting/providing a specific internal file.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata