signals-scout-apm
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). APM span data is ingested at runtime via the integrated APM read-only tools (
apm-spans-aggregate,apm-spans-sparkline,apm-spans-tree,query-apm-spans,apm-trace-get), and these tool responses can include outsider-authored free text from instrumented requests (e.g.,exception.message/ attributes), which the workflow then reads and uses as report evidence without selecting specific items by attacker-controlled source.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata