databricks-mlflow-evaluation
Warn
Audited by Snyk on Feb 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). This skill explicitly ingests user-generated production traces (e.g., via mlflow.search_traces and eval_dataset.merge_records in patterns-datasets.md / patterns-evaluation.md / patterns-judge-alignment.md) and then reads and uses those trace contents in evaluate(), judge alignment (align()), and optimize_prompts(), so untrusted third-party inputs are consumed and can materially influence scoring and downstream actions.
Audit Metadata