alicloud-acs-agent-sandbox
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Runtime path
python3 .../scripts/inspect_agent_sandbox.pyingests Kubernetes resource JSON (e.g., Sandbox/SandboxSet/SandboxClaim and warning Event messages) from the cluster viakubectl ... -o json/kubectl get events ..., where outsider-authored fields like.status.message/event.message/.reasoncan be attacker-controlled through their own CRs/events.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata