agentforce-d360-analyze

Warn

Audited by Snyk on Aug 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). Skill fetch_dc.py reads and LLM-renders first-party Data Cloud STDM/GenAI DMO rows for a specified Agentforce session (e.g., gateway_request.prompt__c, generations.responseText__c, messages.ssot__ContentText__c), but those texts are not authored via an outsider-writable submission path that the workflow monitors without the user first selecting a specific session id.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 7, 2026, 01:00 PM
Issues
1
Security Audit — snyk — agentforce-d360-analyze