signals-scout-data-pipelines
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The skill ingests free-text only from its own first-party internal tools (e.g.,
inbox-reports-list/retrieve,scout-scratchpad-search,cdp-functions-logs-retrieve,workflows-logs), where the arbitrary text originates from pipeline logs/errors for diagnostics but there is no outsider-authored submission path into a queue/feed that this workflow reads.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata