kelly-devops
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Busabase runtime path
content/kelly-devops-app/app/js/providers/busabase-provider.jsreads entire Bases/records (runtimeClient.records.listforservices,expiries,actions,events, etc.) and the AirApp renders those free-text fields into UI viacontent/kelly-devops-app/app/app.js→operations-views.js, so outsider-authored text can be injected by publishing records into those Bases for the workflow to consume.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata