sales-coaching
Warn
Audited by Snyk on Apr 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The SKILL.md Step 1 "Collect Sales Data" explicitly pulls prospect-generated email replies, call transcripts, and recording URLs from third-party tools (e.g., Outreach/Smartlead, Gong/Chorus/Fireflies, Salesforce/HubSpot) and the agent is expected to read and interpret that content to drive analysis and coaching decisions, which could allow adversarial or untrusted third-party text to influence tool behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata