kelly-audit
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime, the AirApp loads user/outsider-authored free text from Busabase records—e.g., anomaly fields like
draft,reason,customer, and evidence rows—viaapp/app/js/providers/busabase-provider.jsgetState()→readAllRecords("anomalies")/buildSnapshot()and then renders them inapp/app/app.js/app/app/js/audit-views.js(including editabledraftandagent_notes).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata