factory-files
Warn
Audited by Snyk on Aug 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/validate_factory_files.py, the workflow reads the user’s repository “resource” files’ UTF-8 content from paths under the provided<factory-root>(e.g.,factory.yamlandagents/**/agent.md, plus related schema-bearing files) and submits that free text toPOST /api/v1/factory-files/validate, so outsider-authored repository content is ingested at runtime via the factory root’s file tree.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata