flaky-smoke-tests
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow uses Azure DevOps CLI to fetch and read pipeline timeline/log lines (task logs and job artifacts) for failed smoke-test iterations from the specified build and log IDs, which are outsider-authored free text inputs to be ingested (e.g., test output, request/response content) without any “trusted author” restriction.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata