docusign
Warn
Audited by Snyk on Apr 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs the agent to call third‑party DocuSign endpoints (e.g., the userinfo endpoint and envelope/document download endpoints like /restapi/.../documents) and to list/download user-generated envelope documents and templates, which the agent would read or act on as part of its workflow and thus could contain untrusted instructions that influence subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata