kill-ai-slop
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required workflow, the scanner (
scripts/scan.mjs) reads and greps the user-provided project source tree from a localrootdirectory (including.md/.mdxcontent) and produces LLM-relevant extracted free text (“file:line” snippets), so an outsider can supply those files by submitting/committing/creating the project content that the workflow scans.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata