qa-security-testing
Warn
Audited by Snyk on Aug 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Source code feeding into the required runtime workflow occurs via files provided to
scripts/vuln_tracker.py(e.g.,--input data/sample-vulnerabilities.json), which can contain outsider-authored free text (like vulnerability titles) that is then read and embedded into the generated Markdown report.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata