coda

Warn

Audited by Snyk on Apr 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). This skill's runtime script (scripts/coda_export.py) calls the Coda API (e.g., fetch_all_pages and fetch_page_content which GET https://coda.io/apis/v1/docs/{doc_id}/pages/... via get_json) to fetch user-generated Coda document content and ingests it into the export workflow, so arbitrary third‑party doc content could influence downstream agent behavior (indirect prompt injection).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 27, 2026, 06:47 PM
Issues
1