uipath-case-management
Warn
Audited by Snyk on Apr 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly fetches and ingests external resource metadata (e.g., "uip maestro case registry pull", "uip maestro case registry get-connector"/get-connection and "is resources describe") and reads the cached registry files (~/.uipcli/case-resources/) as part of its planning and execution flow, and that untrusted third-party connector/action/registry metadata is used to determine task schemas, bindings, and CLI actions—so third-party content can materially influence agent decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata