tldr
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Within the required workflow, the only outsider-authored free text ingested at runtime is the conversation (user messages), and repo evidence is read only from git state; there is no described ingestion of external feeds/inboxes/issue bodies that an outsider can post into a queue/feed the workflow reads.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata