terminology-review
Warn
Audited by Snyk on Jul 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The runtime workflow is a terminology review that can read “applicable glossaries, style guides, neighboring human-authored text” and uses external pages as “untrusted evidence,” meaning if any of that “surrounding files” or fetched evidence is outsider-written prose, it can be ingested into the agent’s LLM context via the review/evidence-reading steps; exclusion does not apply because the procedure explicitly contemplates external/repository/outside text as LLM-readable evidence.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata