blast-radius
Warn
Audited by Snyk on Aug 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The required runtime workflow (“blast radius” steps) instructs the agent to read a user-provided change/diff and then inspect pinned library source it calls; it does not include a workflow step that ingests outsider-authored free text from an external feed/queue/inbox without first selecting specific provider-authored items.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata