oce-mcp-integration
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The MCP runtime workflow ingests assistant-invoked tool inputs (e.g.,
search_cost_itemsaccepts user-providedqand forwards it toGET /api/v1/costs/?region=...&q=..., and other tools accept free-text/BIM element descriptions) but it is not described as monitoring arbitrary outsider-submitted sources like email/chat/queues or reading external issue/support text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata