pipefy-observability
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). [Observability skill reads AI agent and automation execution logs via MCP tools (
get_ai_agent_logs,get_ai_agent_log_details,get_automation_logs*, and CSV export), which necessarily include free-text content authored by end users/external actors present in those logs at runtime (e.g., message bodies, ticket/comment text, or other event payload text recorded by the automations).]
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata