tk-to-spec
Warn
Audited by Snyk on Aug 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). tk-to-spec은 명시적으로
/tk-to-spec또는$tk-to-spec을 선택한 경우에만 실행되며, 런타임에서는 “대화, issue, artifact, repository 조사 결과 등 실제로 읽을 수 있는 source evidence”를 분류해.tigerkit/spec.md에 쓰는 것으로 정의되어 있어 외부 사용자가 올린 free text(예: 대화/issue 등)를 에이전트가 직접 입력으로 읽을 경로가 존재합니다.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata