strix-review
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Runtime path reads free text from the repo-local branch-scoped inbox file
.git/strix/comments.jsonviastrix comment list --json, and that file can contain human-authored comment bodies (text/context) from outside the agent.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata