retrospective
Warn
Audited by Snyk on Jun 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). Multi-session mode reads and parses JSONL session transcripts from
~/.claude/projects/*/*.jsonl, extractinguser/assistantmessagemessage.contenttext blocks into the LLM context; those transcripts can include outsider-authored free text (e.g., other participants’ messages) that the operating user did not choose to introduce.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata