learn
Warn
Audited by Snyk on Jun 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Runtime inputs include
specs/archive/<spec-name>.md(hereevals/inputs/specs/archive/login.md), which is outsider-authored spec body text not written by the operating user, and it is ingested as readable prose into the agent context for generatingspecs/archive/login.learn.md.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata