channel-email
Warn
Audited by Snyk on Jun 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required runtime workflow ingests only admitted email as a structured LionClaw channel turn (with “Latest message (untrusted external input)”), and the host-side worker fetches full bodies only after sender approval; thus the outsider free text is the email body/content authored by external senders that becomes LLM-readable message text in the runtime turn.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata