architect
Warn
Audited by Snyk on Aug 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). During
/architectStage (c) the workflow can run a “Fetch from the web” researcher subagent (tool landscape and Agent Skill or MCP discovery), and it then ingests the free text extracted from web pages/registry results returned by that external browsing at runtime, before writing the spec.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata