Cortex
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The
/cortex recallworkflow runsContextSearch.tsat runtime, which reads local Conversation JSONL/user messages and ISA/work files (e.g.,~/.claude/LIFEOS/MEMORY/STATE/work.json,session-names.json,WORK_DIRISA.md, and~/.claude/projects/**/*.jsonl) and uses that free-text content to produce snippets/results based on the outsider-supplied query.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata