kelly-llm-gateway

Warn

Audited by Snyk on Aug 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Source text that is produced by outsiders (e.g., Busabase “routes/services/models/settings” records populated via an external usage-ingestion process) is read at runtime by busabaseProvider.getState()/readAllRecords() and then rendered in app/app/app.js (e.g., via state.snapshot.routes, route.note, and anomaly ack_note), without selecting a specific item first.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 25, 2026, 10:37 AM
Issues
1
Security Audit — snyk — kelly-llm-gateway