orchestrating-data-pipelines
Warn
Audited by Snyk on Mar 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill instructs the agent to ingest data directly from external cloud storage/URLs (e.g., integrations/cloud-storage.md and the dbt model example using read_parquet('s3://bucket/raw/events/*.parquet') and DuckDB HTTPFS), which are untrusted/third‑party sources whose contents are read and can drive sensors, jobs, and downstream decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata