kelly-legal-contracts
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required AirApp runtime, the provider
busabaseProvider.getState()reads arbitrary free-text fields from Busabase records (contracts,issues,checks,claims,claim-rules,settings) viaruntimeClient.records.list(...)and passes them intoassembleSnapshot()/normalizeIssueRow()for client-side rendering and rule evaluation, so an outsider who can submit records into those Bases can inject poison text into the desk.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata