harness-eval
Warn
Audited by Snyk on Aug 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Outsider-authored free text from the target repo is ingested at runtime because the skill reads repo files specified by discovery (including referenced T0/T1/T2 markdown) into
inventory_extract.py, writes extracted content intoclaims.md/surfaces.md, and then the Track B/C LLM judges score that text via<RUN_DIR>/claims.mdand<RUN_DIR>/surfaces.md.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata