qa-docs-coverage

Warn

Audited by Snyk on Mar 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The Phase 0 "Context Extraction" workflow explicitly instructs extracting repository content via external tools (e.g., gitingest / repo2txt, including a note to "Replace 'github.com' with 'gitingest.com'") which implies fetching and ingesting public/user-generated code from third-party sites that the agent will read and use to drive audit decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 04:23 AM
Issues
1