distill-sessions

Warn

Audited by Snyk on Jun 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Outsider-authored free text from Claude Code session transcripts is ingested at runtime from ~/.claude/projects/**/*.jsonl (user/assistant message content fields in scripts/ingest.pyscripts/main.pytop.jsonClaude reads top.json and includes session events in the Stage 3/5c Agent() prompt), so the LLM context can contain arbitrary text authored by the operating user’s collaborators/other participants in those sessions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 17, 2026, 05:06 PM
Issues
1
Security Audit — snyk — distill-sessions