deployment-approval-call
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The required workflow drives the
phone-approval-gateapp using a locally provided request file and only treats the phone call summary/transcript (gate conversation data) as untrusted input, but it is not shown that outsider-authored free text can be posted into a monitored queue/feed that the gate reads before selecting a specific item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata