recipe-draft-email-from-doc
Warn
Audited by Snyk on Jul 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). This workflow reads body text from a Google Doc at runtime (outsider-authored if the doc content wasn’t authored by the operating user) and injects it into the LLM context via the
gws gmail +send --body 'CONTENT_FROM_DOC'step.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata