analyze-run
Warn
Audited by Snyk on Jul 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.72). SKILL.md Step 3/4 instructs fetching failure summaries and debug info for a user-supplied runId via
npx convex run ... debugQueries:getFailedEvalsForRunanddebug:getEvalDebugInfo, then embedding fields likefailureReason,failedSteperror text,evalSourceFiles(expected answer/grader), andeval.taskinto the sub-agent prompt—these contents are authored by the eval system/other contributors, so they can include outsider free text that becomes LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata