identity-trace
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/identity_trace.py, theingestruntime workflow (ingest_command→load_ingest_payloadfrom--input/stdin) ingests outsider-provided JSON fields liketitle,snippet,query,url, andobserved_atand writes them into the LLM-reported case bundle.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata