project-metrics-orid

Warn

Audited by Snyk on Jun 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). 运行时 /prjmx:collect 会从配置的外部系统 API(data_source/bug_source/git_source/ci_source)拉取项目/缺陷/代码/CI 的文本字段(如标题、状态变更、PR/issue 关联等),这些属于“操作用户未选择引入的第三方内容”,并会进入后续 LLM 上下文用于指标与 ORID 生成。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 23, 2026, 07:29 AM
Issues
1
Security Audit — snyk — project-metrics-orid