pipa-status-update
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow’s Step 2 explicitly reads “Pipa system records (Jira, Linear, ClickUp, Asana, Trello)” and Step 2/3/4 also include “communication signals (Slack, comments, email threads),” which are outsider-authored free text inputs that the workflow may ingest without first selecting a specific item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata