pre-send-qa

Warn

Audited by Snyk on May 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's Mode A workflow explicitly fetches campaign/draft content from third-party ESPs (e.g., Klaviyo via get_campaign, Mailchimp via tool_get_campaign, Get a Newsletter via tool_get_draft/tool_get_sent) and then parses the returned HTML/body for merge tags, links, and instructions as part of its required QA steps, which clearly ingests untrusted/user-generated web content that can influence decisions and subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 2, 2026, 06:43 AM
Issues
1
Security Audit — snyk — pre-send-qa