readme-writing-weapon
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required workflow reads the user-provided repo’s existing README text at runtime (“If a
README.mdalready exists, read it fully”), which is outside-authored content from other contributors/parties and can be used as free text inside the agent’s LLM context via repository file ingestion.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata