aris-result-to-claim
Warn
Audited by Snyk on May 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The workflow explicitly instructs the agent to ingest third-party experiment data (e.g., wandb.Api().run("//<run_id>").history()) and external logs (ssh tail), which are untrusted/user-generated sources that the agent reads and whose content directly influences Codex judgments and routing decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata