findings-to-ado-backlog
Warn
Audited by Snyk on Aug 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow reads external user files (spreadsheets, audit reports, CSVs, meeting notes) provided by the user via local paths or paste input, which can contain untrusted external text. However, because user-provided local files and direct inputs are treated as local/tenant data rather than actively monitored/unfiltered public outsider-authored feeds (such as Jira, GitHub issues, or email feeds), this ingestion falls under low/active local file extraction.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata