llm-obs-eval-bootstrap
Warn
Audited by Snyk on Jun 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required runtime workflow in publish mode ingests outsider-authored free text from production LLM trace/span content (e.g., user messages and model outputs) via MCP tools like
search_llmobs_spans/get_llmobs_span_contentand then embeds that content into LLM-judge prompt templates for evaluator creation/scoring; this trace text is not authored by the operating user and is therefore outsider free text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata