audit-harness-usage

Warn

Audited by Snyk on Aug 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In scripts/audit_harness_usage.py, the required runtime workflow auto-discovers and reads locally stored provider trace files (e.g., Codex sessions under $CODEX_HOME/{sessions,archived_sessions} and Gemini chats under ~/.gemini/tmp/**/chats/session-*.json, plus optional explicit exports via --path PROVIDER=PATH) that can contain outsider-authored free text in their metadata without the script selecting specific messages first.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 12, 2026, 05:26 PM
Issues
1
Security Audit — snyk — audit-harness-usage