why

Warn

Audited by Snyk on Aug 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Source control, PR, issue/ticket tracker, long-form docs, chat, observability, error tracking, and analytics evidence are all fetched/read at runtime by the investigators using enabled MCPs (Step 3 “queries all seven in parallel”), which can include outsider-authored free text from non-first-party users (e.g., issue comments, chat messages, Sentry event text, ticket descriptions/attachments).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 04:26 AM
Issues
1
Security Audit — snyk — why