auto-workflow
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Analyze mode, the workflow takes outsider-authored URLs from
${var}and performsWebFetch(plus fallbacks like/robots.txt//sitemap.xml/gh api/token-site fetch) to extract page text/signals, so free text from arbitrary third-party sources is ingested at runtime before any specific item selection step beyond “for each remaining URL”.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata