crg-design-gen

Warn

Audited by Snyk on Aug 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The crg_req_to_design/crg_req_pipeline workflow consumes a user-provided requirement table file (e.g., req.xlsx/CSV/XLS) from the MCP/CLI input path and turns its free-form cells (notes/frequencies/names) into LLM-ingested content at runtime, so an outsider can submit poison via the workflow’s required input without preselecting a specific item.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 17, 2026, 02:01 AM
Issues
1
Security Audit — snyk — crg-design-gen