gtm-account-scoring

Warn

Audited by Snyk on Aug 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The runtime workflow reads first-party GTM context files (target node icps/*.md under ~/.gtm/<org-slug>/...) and never “enriches” by opening external links, but it directly ingests the user-supplied Label as an input while validating it against those visible ICP labels.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 7, 2026, 03:45 PM
Issues
1
Security Audit — snyk — gtm-account-scoring