agency-os
Warn
Audited by Snyk on Jul 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider-authored free text from the Notion workspace (task page “Description” toggle body and latest “Discussion log” entry) is fetched at runtime via the Notion MCP/REST (
notion-fetchpreflight andfetch_description_preview/ page content) and then inserted into the LLM’s kickoff brief/context for/agency-os startand batch/agency-os runexecution.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata