truefoundry-gateway

Warn

Audited by Snyk on May 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to call and integrate external OpenAI‑compatible/provider endpoints and third‑party guardrail integrations (e.g., "Custom (Any OpenAI‑Compatible Endpoint)" in references/provider-templates.md and the integration/guardrail/custom type in references/guardrail-providers.md and guardrails-setup.md), meaning it ingests and acts on responses from arbitrary external APIs that could contain untrusted/user-generated content and therefore influence subsequent decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 19, 2026, 09:28 PM
Issues
1
Security Audit — snyk — truefoundry-gateway