detect-stale

Warn

Audited by Snyk on Jul 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). The required workflow fetches outsider-authored free text by reading feature request records’ title and especially description (“Fetch all open feature requests… Collect … description”) from an external system via wccom-feature-requests-list, then includes that description content in LLM-visible prompts (e.g., Step 4 “trimmed … description” and Step 5 “Show full group details … [description — first 2–3 sentences]”).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 24, 2026, 03:47 AM
Issues
1
Security Audit — snyk — detect-stale