contact-sync
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). At runtime, Step 2 ingests Gorgias ticket data (customer emails/names) via
composio execute GORGIAS_LIST_TICKETS, and Step 3 ingests HubSpot contact data viacomposio execute HUBSPOT_SEARCH_CONTACTS_BY_CRITERIA; these are outsider-authored customer/support records not authored by the operating user, and the extracted prose/fields are then fed into the agent’s LLM context for the report.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata