vip-alert
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Outsider free text can enter the LLM context via Step 2/3 tool outputs:
composio execute GORGIAS_LIST_TICKETSreturns open support ticket content authored by external customers/agents, and the agent then uses that ticket text (and customer-provided issue descriptions) to populate the VIP dashboard/Slack message.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata