openspec-apply-change
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The required workflow reads “contextFiles” (file paths) returned by the runtime output of
openspec instructions apply --jsonand then reads those files’ contents into the agent context (step 4), where those artifacts can be authored by outsiders in an OpenSpec change/repo (e.g., public or third-party repos), creating indirect prompt-injection risk.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata