extract-controls
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In extract_controls.py, the extract-text subcommand ingests the outsider-provided inline
--textargument and immediately runs regex/RapidFuzz candidate extraction plus optional catalog resolution before producing outputs (and the larger pipeline queues proof_jobs withrequirement_text).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata