scheduled-summary
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow reads outsider-authored free text from user-configured local sources—session SQLite “messages.content” and other TODO-like text, cron output files (.md/.txt/*.log), memory JSON “fact/memory/content/text/summary/title”, log files, and Markdown decision records—via
scripts/summarize.py generatepath resolution (e.g.,--sessions-db,--cron-dir,--memory-dir,--log-file,--decisions-dir) so an outsider who can submit/poison those inputs can cause ingestion without selecting a specific item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata