cocoindex
Fail
Audited by Snyk on Jun 20, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt explicitly tells the agent to ask the user for missing LLM API keys and to use real API key values in flows/examples (including patterns that place secrets into .env or pass them to functions like add_transient_auth_entry), which forces the LLM to handle/output secret values verbatim and creates exfiltration risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The required runtime workflow reads source document text via configured sources (e.g.,
flow_builder.add_source(cocoindex.sources.LocalFile(...))/ S3 / Postgres) and then passes that extracted prose into LLM-ingesting transforms likecocoindex.functions.ExtractByLlm(..., instruction=...), so if the source content is outsider-authored it becomes LLM context (indirect prompt injection risk).
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata