second-brain-review

Warn

Audited by Snyk on Jul 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). Outsider-authored free text can be ingested because scripts/pick-review.py reads markdown files from the runtime --vault (e.g., wiki/sources/*.md, wiki/concepts/*.md, and wiki/log.md) and returns their extracted prose in JSON (items[].text / items[].page), which the agent would then place into the LLM context for the “Present the Review” step.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 05:06 PM
Issues
1
Security Audit — snyk — second-brain-review