spec-grill
Warn
Audited by Snyk on Jun 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider-authored free text from the target repo is ingested at runtime via
scripts/extract-signals.jsreadingREADME.md,spec/charter.md(and legacyCHARTER.md),spec/system-map.md,CLAUDE.md/AGENTS.md, plus other.mdfiles and commit messages, then returning them as JSON/human report that the agent can place into its LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata