pre-send-qa
Warn
Audited by Snyk on May 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Mode A workflow explicitly fetches campaign/draft content from third-party ESPs (e.g., Klaviyo via
get_campaign, Mailchimp viatool_get_campaign, Get a Newsletter viatool_get_draft/tool_get_sent) and then parses the returned HTML/body for merge tags, links, and instructions as part of its required QA steps, which clearly ingests untrusted/user-generated web content that can influence decisions and subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata