finding-data-lake-assets

Warn

Audited by Snyk on Jul 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). This workflow can ingest customer-authored Glue Discovery catalog fields (Description, Forms, embedded JSON from get-asset/batch-get-iterable-forms) into the agent context, since it explicitly retrieves and uses those untrusted text/metadata at runtime.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 24, 2026, 04:01 PM
Issues
1
Security Audit — snyk — finding-data-lake-assets