budget-pacing-monitor
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
budget-pacing-monitor, the runtime path explicitly reads an in-flight “campaign report CSV exported from the native ad manager” (spend by day, budget, delivery/serving status, etc.) and treats that fetched/exported file as untrusted input that the LLM ingests to compute pacing and triggers.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata