regulatory-alert-analysis

Warn

Audited by Snyk on Aug 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow directly queries ServiceNow tables like sn_regulatory_alert (Step 1) and then uses fields such as short_description/description from those records to drive impact analysis and writes work notes (Step 5), meaning outsider-authored alert text in the monitored table can be ingested at runtime without selecting a specific trusted item.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 3, 2026, 02:24 PM
Issues
1
Security Audit — snyk — regulatory-alert-analysis