grouchygiraffe-recipe-lookup
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The runtime workflow reads a YAML file and a
_thumb.jpgderived from an outsider-provided media path, and then performs WebSearch/WebFetch to fetch arbitrary public web pages/snippets (e.g., the author’s site and search results), which can include outsider-authored free text that may be ingested into the LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata