assist-kitchen
Warn
Audited by Snyk on Aug 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime workflow, the agent ingests outsider-authored free text from the user at runtime via
scripts/kitchen-axi inventory remark "<free text>"(which joins/matches that remark to inventory items and infers events) and potentially via other user-supplied note fields likescripts/kitchen-axi entries log/entries patch(notes/labels are human-entered), so a malicious actor can directly submit poison text that the workflow consumes without selecting a specific pre-existing item first.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata