propose-security-hardening
Warn
Audited by Snyk on Jul 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow ingests user-supplied evidence inputs (disclosure documents, finding writeups, PoCs/traces, and even source trees) directly into the LLM for analysis via steps like “Inventory each input file or directory directly” and “read the relevant disclosure, finding, PoC, trace, and source files themselves,” meaning outsiders can submit poison through the user-provided evidence collection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata