vendor-cyber-risk-analyst
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.72). Outsider free text can enter the LLM context via runtime ingestion of vendor-provided questionnaire answers and evidence/attestation materials (e.g., “Analyze security questionnaires” and “Evidence and attestation review” workflows), which are authored by third parties and may contain prompt-injection-like text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata