verify
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Phase 3 Job B (“Triage Changed Files”), the pipeline explicitly “Read[s] each changed file (not just the extension — look at actual content),” meaning an outsider who authors repository changes can place arbitrary free text into those files that the required workflow and its sub-agents will ingest at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata