docusign

Warn

Audited by Snyk on Apr 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs the agent to call third‑party DocuSign endpoints (e.g., the userinfo endpoint and envelope/document download endpoints like /restapi/.../documents) and to list/download user-generated envelope documents and templates, which the agent would read or act on as part of its workflow and thus could contain untrusted instructions that influence subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 17, 2026, 04:44 PM
Issues
1