okf-bundle
Warn
Audited by Snyk on Jul 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). Required workflow runs
okf_validate.py/okf_index.pywhich read and parse Markdown files under--bundle-root(e.g.,path.read_text(...)andparse_frontmatter), so if those files were authored by outsiders, their free-text frontmatter/body is ingested into the runtime context (and then used to generate outputs).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata