fusion-setup
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In the Fusion setup/normal operation, the only outsider-provided free text ingested at runtime is the user’s chat request passed as part of the Claude Code review “packet” input (plugins/fusion-claude.js → tool execution input → external Claude CLI stdin).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata