ingest
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The required workflow describes ingesting “raw input” that is copied into
sources/YYYY-MM-DD/and then extracting claims from it intowiki/(step 2→3), which would feed outsider-authored free text into the agent’s LLM context if the “source” provided at runtime is from a non-user origin (e.g., public web content or someone else’s issue/PR text).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata