a365-code-validator
Warn
Audited by Snyk on Jul 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow reads and parses free text from the user’s local target project files (e.g., it recursively reads
*.py,*.ts/.js,.env*, and config JSON and the standalone validator concatenates contents and regex-matches them), which is outsider-authored when the repo is authored by an untrusted user.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata