tcga-bulk-data-preprocessing-with-omicverse

Warn

Audited by Snyk on Jul 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). High likelihood: the required workflow loads TCGA clinical files (from a user-provided clinical.cart.<date>/ directory) and sample sheet/archives from GDC downloads; these outsider-authored texts (clinical XML/JSON and TSV) are parsed into runtime Python objects and thus become LLM-readable context via the agent’s “confirm paths / run code” narrative and any surfaced parsing/validation errors/logs.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 22, 2026, 05:43 PM
Issues
1
Security Audit — snyk — tcga-bulk-data-preprocessing-with-omicverse