cloudformation

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill includes CloudFormation patterns that load external templates/snippets (e.g., "TemplateURL: https://s3.amazonaws.com/my-bucket/network.yaml" and "!Transform AWS::Include Location: s3://my-bucket/snippet.yaml"), which cause the agent/workflow to ingest arbitrary S3-hosted third-party content that could be untrusted.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:39 PM