orchestrator

Warn

Audited by Snyk on Mar 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The Plan Workflow (section 3.1 "Source Types") explicitly instructs the agent to fetch and ingest user-generated content from external sources—e.g., "gh issue view --json body,comments", "gh pr view --json body,comments", and "Jira API"—which the orchestrator must read and use to form plans and dispatch workers, allowing untrusted third-party text to influence behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 24, 2026, 06:42 AM
Issues
1