hunting-saas-sso-token-abuse
Warn
Audited by Snyk on Aug 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In scripts/agent.py, the runtime workflow directly pulls and ingests Okta System Log event JSON from the caller-specified Okta org endpoint (via requests.get to https://{org}/api/v1/logs with the filter params), and that event text can include attacker-controlled values like user-agent/ip/session identifiers.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata