session-logs
Warn
Audited by Snyk on Jul 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). This skill reads prior conversation transcripts from local session JSONL files under
$OPENCLAW_STATE_DIR/agents/<agentId>/sessions/, which can include outsider-authored free text from other participants in those chats (e.g., messages/comments not authored by the operating user) and then feeds that historical text into the agent’s LLM context for answering.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata