project-metrics-orid
Warn
Audited by Snyk on Jun 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). 运行时
/prjmx:collect会从配置的外部系统 API(data_source/bug_source/git_source/ci_source)拉取项目/缺陷/代码/CI 的文本字段(如标题、状态变更、PR/issue 关联等),这些属于“操作用户未选择引入的第三方内容”,并会进入后续 LLM 上下文用于指标与 ORID 生成。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata