archive-spec
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The
archive-specworkflow reads outsider-authored Markdown files within the selected<spec-root>/<slug>(e.g.,task_NN.mdlisted in_tasks.md,qa/qa-report-*.md, anddocs/specs/<slug>/references/_index.md) via repository file commands likegrep, YAML parsing, andawkat runtime, without requiring a prior selection of a trusted item beyond the user-provided slug.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata