Skip to content

security(orchestration): gap descriptions from verify LLM flow into replan prompt verbatim #2240

@bug-ops

Description

@bug-ops

Second-order prompt injection risk: gap text from verification LLM flows directly into replan prompt. Add 500-char cap on gap descriptions before passing to replan().

Metadata

Metadata

Assignees

Labels

P3Research — medium-high complexityllmzeph-llm crate (Ollama, Claude)securitySecurity-related issue

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions