k6-cloud-investigate-test

Warn

Audited by Snyk on Aug 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The workflow reads Grafana Cloud k6 run artifacts (metadata, scripts, aggregated metrics, per-check results, and logs) via gcx api endpoints keyed by the user-provided test/run IDs, so an outsider user can submit/own a failing test whose emitted log text/check names/metric labels are then ingested by the investigator at runtime.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 7, 2026, 04:45 PM
Issues
1
Security Audit — snyk — k6-cloud-investigate-test