arkweb-security-patch-merge
Warn
Audited by Snyk on Aug 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). references/input-and-normalization.md + scripts/plan_batch.mjs read outsider-provided patch archive contents from
context.requirements(e.g.,02_patch_fetch.json,03_impact_decision.json, and patch files under the issue archive) and then LLM runtime-ingests/decodes their free text (patch diff/mbox or base64-encoded patch) during normalization.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata