customer-commitment-validation
Warn
Audited by Snyk on Jun 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The workflow ingests the user-provided meeting notes/CRM/narrative (explicitly “notes, transcripts, CRM entries, or a narrative of how a meeting ended”), which are outsider-authored free text when they include the other party’s words, and the LLM would read that text directly from the runtime input.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata