analyze-run

Warn

Audited by Snyk on Jul 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.72). SKILL.md Step 3/4 instructs fetching failure summaries and debug info for a user-supplied runId via npx convex run ... debugQueries:getFailedEvalsForRun and debug:getEvalDebugInfo, then embedding fields like failureReason, failedStep error text, evalSourceFiles (expected answer/grader), and eval.task into the sub-agent prompt—these contents are authored by the eval system/other contributors, so they can include outsider free text that becomes LLM context.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 11, 2026, 03:02 PM
Issues
1
Security Audit — snyk — analyze-run