sales-fireflies
Warn
Audited by Snyk on Apr 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's required workflow (SKILL.md Step 3) and included references explicitly instruct the agent to read the Fireflies API docs and to call the GraphQL API / AskFred operations (e.g., references/getting-started_llm-development.md and graphql-api_* pages such as createAskFredThread and transcript queries) which cause the agent to ingest user-generated transcripts and/or fetch a public URL (https://docs.fireflies.ai/llms-full.txt), meaning untrusted third‑party content can be read and materially influence subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata