account-scoring

Warn

Audited by Snyk on Aug 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The workflow plays/score-accounts.ts feeds an outsider-supplied input.name and input.domain into the accountScorer agent prompt (prompt: \Score the account ${input.name} (${input.domain}).``) and then the agent’s system prompt/LLM can ingest that free text at runtime before scoring and writing the rationale to the CRM.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 18, 2026, 07:44 AM
Issues
1
Security Audit — snyk — account-scoring