start-issue

Warn

Audited by Snyk on Aug 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The runtime workflow only reads first-party repo config files (docs/agents/issue-tracker.md and docs/agents/vcs.md) and then (optionally) fetches a specific ticket only after parsing a user-supplied ticket id/slug, rather than passively ingesting outsider-authored free text from a monitored queue/feed.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 11, 2026, 04:40 PM
Issues
1
Security Audit — snyk — start-issue