contract-delivery-kickoff
Warn
Audited by Snyk on Aug 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required
readruntime workflow, the agent ingests outsider-authored free text by parsing a user-supplied contract Office file (cmd_read→load_document(args.source)→extract_text(path)/document_tables(path)), so an outsider can provide arbitrary.docxcontent that the LLM will read and incorporate into outputs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata