queryable-markdown
Warn
Audited by Snyk on Aug 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/mdq.py, the required runtime workflowfind/run/scan(collection search) ingests outsider-authored free text when it is part of user-provided Markdown inputs that are searched/matched without the agent first selecting a specific pre-known record (e.g.,line_local_search_recordsscans all lines for a literal substring and returns line-local record contexts).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata