signals-scout-health-checks
Warn
Audited by Snyk on Jun 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The runtime workflow reads outsider-authored free text from
health-issues-get→ the issuepayload/title/summaryfields, which are explicitly “project- and event-supplied” and can be set by anyone with the project token or via connected database control, and then the agent uses that text in its LLM context to decide what to emit.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata