terminology-review

Warn

Audited by Snyk on Jul 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). The runtime workflow is a terminology review that can read “applicable glossaries, style guides, neighboring human-authored text” and uses external pages as “untrusted evidence,” meaning if any of that “surrounding files” or fetched evidence is outsider-written prose, it can be ingested into the agent’s LLM context via the review/evidence-reading steps; exclusion does not apply because the procedure explicitly contemplates external/repository/outside text as LLM-readable evidence.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 26, 2026, 08:32 AM
Issues
1
Security Audit — snyk — terminology-review