tk-to-spec

Warn

Audited by Snyk on Aug 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). tk-to-spec은 명시적으로 /tk-to-spec 또는 $tk-to-spec 을 선택한 경우에만 실행되며, 런타임에서는 “대화, issue, artifact, repository 조사 결과 등 실제로 읽을 수 있는 source evidence”를 분류해 .tigerkit/spec.md에 쓰는 것으로 정의되어 있어 외부 사용자가 올린 free text(예: 대화/issue 등)를 에이전트가 직접 입력으로 읽을 경로가 존재합니다.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 12, 2026, 12:10 AM
Issues
1
Security Audit — snyk — tk-to-spec