vibe-togaf-architect
Warn
Audited by Snyk on Jun 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The required workflow reads
exploration/captures/DISCOVERY_REPORT.md(a file authored by someone other than the operating user) and the user’s NFR Q&A transcript, and then ingests that readable text into the agent to generate the/specsfiles—so outsider-authored free text can enter the LLM context via the discovery report file path.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata