kelly-launch
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
content/kelly-launch-app/app/js/providers/busabase-provider.js, the app runtime reads all Busabase record text foritems,channels,runbook, and thekelly-launch-profilesettings payload viaprovider.getState()→readAllRecords(...)→runtimeClient.records.list(...), so any outsider-authored strings stored in those records are ingested and then rendered in the UI (e.g.,draft,title,reason,note).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata