application-visualizer-refresh
Warn
Audited by Snyk on Jun 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). At runtime the script reads and parses free-form markdown text from outsider-authored tracker files (e.g.,
application-trackers/applications.md,outreach-prospects.md,job-intake.md) viaargs.applications.read_text()/extract_tables(...), then injects the resulting prose fields (notablyNotes) into the generated JSON/LLM-readable context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata