sandcastle-runner

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). Runtime path sandcastle_runner.run_sandcastle() launches npx sandcastle run and streams the subprocess stdout line-by-line into session.logs after only regex redaction; Sandcastle (and any embedded prompts it uses) is not operating-user-authored, so its free-text output can include outsider-authored content that becomes LLM context via the dashboard/session log pipeline.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 08:04 AM
Issues
1
Security Audit — snyk — sandcastle-runner