magi
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
references/scripts/magi-run.sh→run_sage()→dispatch_round(), the host-suppliedprompt/user question is written to${out_dir}/question.mdand then piped/loaded from${out_dir}/<round>/prompt*.mdinto each sage CLI via stdin or{PROMPT_FILE}, meaning outsider-authored free text can be ingested by the runtime workflow immediately.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata