convex-self-heal
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required workflow, prod error details are first ingested from the user’s own “sentinel” table via the MCP run-once-query/monitor event (steps 2–3) and then the agent uses that evidence (including the reproducing input) to triage/root-cause and certify fixes (steps 4–7), so outsider-authored free text is read at runtime if it was submitted into prod errors by a third party.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata