finance-substrate
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). High: the
dian-fillworkflow generatesagent-browsercommands based on values computed fromtax_projection.py, which in turn ingests outsider-authored free text from Gmail email bodies (e.g., Thera “You just received a payment!”) viascripts/gmail_collector.py→get_message_body()→ regex parsing, and those extracted strings/values are then embedded into the LLM context when the agent runs the skill and uses the generated fill plan.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata