feed
Warn
Audited by Snyk on Jun 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). Outsider-authored free text is ingested when
fetch-feeds.rbfetches runtime RSS/Atom content from public URLs infeeds.yaml(e.g., NVD, Snyk, GitHub Security Blog) and parsesitem.title/item.descriptionorentry.summaryintoitems, which are then passed into the LLM analysis/reporting context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata