redmine-cli

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The CLI fetches data from arbitrary Redmine servers specified in ~/.red/config.json (base URL) and calls endpoints such as /issues.json and /issues/:id.json (including journals), thereby ingesting untrusted, user-generated issue descriptions and comments that the agent reads and outputs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:32 AM