pipefy-observability

Warn

Audited by Snyk on Aug 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). [Observability skill reads AI agent and automation execution logs via MCP tools (get_ai_agent_logs, get_ai_agent_log_details, get_automation_logs*, and CSV export), which necessarily include free-text content authored by end users/external actors present in those logs at runtime (e.g., message bodies, ticket/comment text, or other event payload text recorded by the automations).]

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 1, 2026, 01:08 AM
Issues
1
Security Audit — snyk — pipefy-observability