pipa-work-coordination
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The workflow ingests execution evidence from potentially outsider-authored sources like Slack standup notes/comments, Notion comments, and especially GitHub issues/PRs via “latest standup notes, comments, and handoff records” and “Continue from other usable execution evidence when safe” after composio-mcp tool discovery, which can include free text submitted by external users.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata