case-summarization-approvals
Warn
Audited by Snyk on Aug 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). At runtime the workflow fetches and LLM-ingests outsider-authored free text stored in ServiceNow records—e.g., Step 3 extracts justification from catalog variable question_text/value and Step 3 also pulls journal/comments from sys_journal_field for the source case/request, then Step 5 pulls approver comments.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata