log-to-dosu-knowledge

Warn

Audited by Snyk on Aug 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The runtime workflow reads and digests local Cursor/Claude/Codex JSONL agent logs from paths under ~/.cursor/projects/.../agent-transcripts, ~/.claude/.../projects/.../*.jsonl, and ~/.codex/sessions/.../*.jsonl (via parse_agent_logs.py), which can contain outsider-authored free text submitted in those agents’ user turns.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 01:32 AM
Issues
1
Security Audit — snyk — log-to-dosu-knowledge