payment-invoice-lookup
Warn
Audited by Snyk on Jul 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). During workflow steps 5A/5B the agent issues
well_query_recordsagainst Well’s MCP server to readinvoices,transactions, andinvoice_transactions, using user-supplied lookup fields (invoice/transaction/date/amount/counterparty or time window) to select specific records, so outsider-authored text is not ingested as free content but only as structured search parameters.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata