doca-upgrade

Warn

Audited by Snyk on Jul 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). Exclusion: the required runtime workflow for doca-upgrade primarily ingests first-party bundle text (SKILL.md/CAPABILITIES.md/TASKS.md and outputs from internal companion skills like doca-version), and while it may look up “public release notes” via doca-public-knowledge-map, there is no required runtime step here that ingests arbitrary outsider-authored free text without first selecting trusted, specific sources.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 05:24 PM
Issues
1
Security Audit — snyk — doca-upgrade