recipe-save-email-to-doc

Warn

Audited by Snyk on Jul 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). This workflow pulls an outsider-authored Gmail message body (from an external sender like boss@company.com) via gws gmail users messages get, then injects that free-form email text into the LLM context through the gws docs +write --text ... [EMAIL BODY] step.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 15, 2026, 01:28 PM
Issues
1
Security Audit — snyk — recipe-save-email-to-doc