expansion-opportunity-analysis

Warn

Audited by Snyk on Jul 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Skill.md requires the agent to search for and pull deal history from the user-provided {{CRM}} and query monthly usage from {{USAGE_SOURCE}}, meaning outsider-authored free text could be ingested if the CRM/usage system contains user/third-party submitted fields (e.g., deal notes, support/QBR thread text) that are read without first selecting a specific item.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 04:39 PM
Issues
1
Security Audit — snyk — expansion-opportunity-analysis