event-signals
Warn
Audited by Snyk on Jul 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required workflow fetches outsider-authored free text from public web/API sources (e.g., Sessionize speaker bios/talk descriptions, Meetup/Luma event descriptions, ListenNotes episode descriptions, Devpost project titles/taglines) via runtime HTTP requests in
scripts/event_signals.py, then writes that text into the tool’s output fields (CSV/JSON) that the agent can subsequently read into LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata