dx-devops-promote
Warn
Audited by Snyk on Aug 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The required runtime workflow only ingests attacker-controlled free text indirectly via explicit record identifiers passed as
--work-item-id/--stage-idflags, and all authoritative decisions (e.g., combining) are derived from first-party CLI JSON outputs (sf devops promotion validate --json) rather than from untrusted natural-language text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata