dumc-email-to-obsidian-notes
Warn
Audited by Snyk on Jun 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). The required workflow ingests readable email body text from outsider-authored CSU mailbox messages via Microsoft Graph pulls (e.g.,
/meand probed shared/role mailboxes), and that message content is then summarized and written into the agent’s LLM context for note creation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata