learn-datalake
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Source
learn-datalakewatches/ingests user-provided directory contents and feeds extracted requirement/passage text into the/match-requirementpipeline for autonomous requirement-to-control matching, so outsider-authored document text can reach the runtime LLM via the extraction→chunk→matching flow.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata