cxas-loss-analysis
Warn
Audited by Snyk on Jul 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s required runtime workflow fetches and reads CCAI Insights conversation transcripts via
fetch_losses.py(callinginsights_client.list_conversations(..., view="FULL"), extracting segmenttext, thenSKILL.mdStep 3 reads{output_dir}/raw_losses.jsonand its transcript chunk files for LLM analysis), and those transcripts are outsider-authored (end-customer free text).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata