legal-incident-response
Warn
Audited by Snyk on Jun 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text can enter the LLM context via the authority-letter path’s
incoming_letter_text/incoming_letter_summaryinputs (Step 3 EXTRACT and Step 4 DRAFT inprotocols/authority-letter.md), where the pasted letter content is authored by an external regulator and is then read by the LLM.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata