report-generator
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/generate_report.py, the runtime ingests user-supplied JSON files (breakdown_jsonand optionallyhook_analysis_json) from local paths/arguments and directly inserts their free-text fields (e.g.,visual_content,*_comment,strengths/weaknesses/suggestions,platform_recommendations[].reason) into the generated Markdown without filtering, so outsiders can submit poison via those inputs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata