ingest

Warn

Audited by Snyk on Jul 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). The required workflow describes ingesting “raw input” that is copied into sources/YYYY-MM-DD/ and then extracting claims from it into wiki/ (step 2→3), which would feed outsider-authored free text into the agent’s LLM context if the “source” provided at runtime is from a non-user origin (e.g., public web content or someone else’s issue/PR text).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 25, 2026, 08:52 AM
Issues
1
Security Audit — snyk — ingest