kelly-social
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime path that ingests outsider-authored free text is the app’s Busabase “posts”/“engagement” records (fields like
posts.textandengagement.incoming_text) loaded by the AirApp client and rendered into the UI, so any user-controlled content written into those Bases could flow into the LLM during gate evaluation/drafting.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata