investigation-entrypoint
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow ingests PagerDuty/incident-context input and immediately uses it to trigger
gcp-architecture-discoveryand subsequent logging/metrics investigation, meaning outsider-authored incident/event text delivered via the PagerDuty→integration path could be read by the subagents/tools before any filtering for a specific item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata