obproxy-log-analysis
Warn
Audited by Snyk on Jun 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). OBProxy 日志采集后会在运行时对采集输出目录中的日志文件进行
file_read(或先用run_shell解压后再file_read),而这些日志正文属于“操作用户未撰写的外部系统/他人产生的文本”,从而可能把 outsider-authored free text 注入到 LLM 上下文。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata