run-delivery-chain
Warn
Audited by Snyk on Jul 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Runtime path:
driver.shcreates a temp host repo and writes a JSONL transcript containing a fencedstatusblock, then passes{"agent_type":..., "transcript_path":...}topython3 scripts/agent_memory_hook.py subagent-stopvia stdin; the hook reads that outsider-authored transcript text from the filesystem and injects it into the LLM context duringsubagent-start(viaadditionalContext).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata