scrape-codegen
Warn
Audited by Snyk on Jul 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required workflow reads outsider-authored free text from
{spec_path}/spec.json,{spec_path}/pages/*/{raw.html,rendered.html}, and{spec_path}/values/*(which are produced by/scrape-specand thus can include scraped page HTML and extracted content) and then passes them into the LLM via/scrape-codegen-analyze ... {spec_path}/spec.json {spec_path}/values/{page_id}.json.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata