mantis-reflect
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill reads and parses the other agents’ runtime execution logs (e.g.,
transcript.jsonl/conversation.jsonl) to extract trajectories, which are outsider-authored free text from other agents’ messages/tool outputs that the operating user did not author directly.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata