summarise-granola
Warn
Audited by Snyk on Jun 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required runtime workflow ingests Granola meeting transcript text fetched via the Granola API (
scripts/granola.py get→build_transcript()→ transcript markdown saved underdata/transcripts/→ passed as “full raw transcript text” into the summary agent prompt), and that transcript is outsider-authored content (other meeting participants’ speech) that can contain indirect prompt-injection strings.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata