approval-workflows
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md describes runtime logic that queries ServiceNow approval-related tables via
snow_query_table/snow_artifact_manage(e.g., readingsysapproval_approver,sysapproval_rule) based on a provided query, which could cause the agent to ingest outsider-authored text if the attacker can influence what records/fields are returned (e.g., approval comments or rule/script fields) without selecting a specific item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata