diy-harness
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime workflow, the agent’s Turn A explicitly “Explore the project (repo, CMS, Carrd, or mixed)” to write
docs/harness-audit.mdand generate the readiness score/tasks, meaning it ingests outsider-authored free text from the user’s project contents before selecting specific items.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata