cx-cases
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Runtime path reads case/timeline comment free text only after the workflow first selects a specific case (e.g.,
cx cases get <id>/get_alerts_objectfor one case, then summarizescomment_textin that case’s event output), so outsider-authored text is ingested only in a targeted per-case flow.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata