semantius-modeler

Warn

Audited by Snyk on Aug 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In semantius-modeler Stage 1/Step 1 runtime, the agent reads the user-provided *-semantic-spec.md file produced by semantius-analyst (“Locate the *-semantic-spec.md file”), then parses multiple free-text fields (descriptions, JsonLogic message/description, enum labels, and Select rule/Validation rules objects) from that file into the model and uses them to execute Semantius writes via Stage 4.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 9, 2026, 11:06 PM
Issues
1
Security Audit — snyk — semantius-modeler