scaffolding-api-routes
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow reads legacy API contract documentation from
docs/legacy-audit/API_Contracts.md(outsider text category: documents the operating user did not author), which would be ingested by the scaffold subagent when it “locate[s] and read[s]” that file at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata