security-alerts
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). At runtime the required workflow reads outsider-authored free text from GitHub Dependabot alerts and ADO/GitHub-provided alert/work-item content (via
gh api repos/.../dependabot/alerts,az boards query, andaz boards work-item show), which are then ingested and merged into the LLM fix plan.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata