cursor-transcript-harvest
Warn
Audited by Snyk on Jul 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow runs
pnpm harvest:all/host/devcontainer --unpack, which harvests Cursor transcript files from~/.cursor/projects(host/devcontainer paths) and then normalizes/feeds them into the agent’s LLM context; these transcripts are outsider-authored free text (e.g., other people’s chat/code comments) unless the user explicitly authored them.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata