run-delivery-chain

Warn

Audited by Snyk on Jul 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Runtime path: driver.sh creates a temp host repo and writes a JSONL transcript containing a fenced status block, then passes {"agent_type":..., "transcript_path":...} to python3 scripts/agent_memory_hook.py subagent-stop via stdin; the hook reads that outsider-authored transcript text from the filesystem and injects it into the LLM context during subagent-start (via additionalContext).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 4, 2026, 02:08 PM
Issues
1
Security Audit — snyk — run-delivery-chain