predictive-intelligence

Warn

Audited by Snyk on Aug 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md describes an ES5 ServiceNow PI workflow that ingests text from ServiceNow records at runtime (e.g., calling sn_ml.ClassificationPredictor.predict(gr) or predict(current) using fields like short_description/description), where outsider-authored incident/case content can be present in those records.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 9, 2026, 11:30 PM
Issues
1
Security Audit — snyk — predictive-intelligence