qa-loop
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The QA loop ingests “incoming issue” evidence as text/screenshots/recordings/logs from the user-supplied queue (“Phase 3: Intake and Queue Issues” and “Phase 4: Reproduce and Diagnose”), and explicitly treats embedded text/page content/console output/network payloads as untrusted evidence that the workflow reads at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata