propose-security-hardening

Warn

Audited by Snyk on Jul 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The required workflow ingests user-supplied evidence inputs (disclosure documents, finding writeups, PoCs/traces, and even source trees) directly into the LLM for analysis via steps like “Inventory each input file or directory directly” and “read the relevant disclosure, finding, PoC, trace, and source files themselves,” meaning outsiders can submit poison through the user-provided evidence collection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 29, 2026, 05:31 PM
Issues
1
Security Audit — snyk — propose-security-hardening