materialize-roadmap-threads

Warn

Audited by Snyk on Jul 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The required workflow reads roadmap.md and each CB<N> brief’s free-form fields (including Outcome, Context, Scope and boundaries, Dependencies, Relevant shared constraints, and Suggested workflow) from the parent thread’s docs/threads/.../roadmap.md at runtime, and those texts are then copied verbatim into the LLM context passed to /allocate-thread (indirect prompt-injection risk if any of that content was authored by an outsider).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 16, 2026, 08:33 PM
Issues
1
Security Audit — snyk — materialize-roadmap-threads