strands-evals
Warn
Audited by Snyk on Jun 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). Chaos testing uses
ChaosPluginto inject chaos into tool-result text blocks (JSON/text) via Strands hook events (after_tool_call→_apply_to_blocks), and those corrupted tool outputs are then included in the evaluation trajectory/LLM-judge context; the injected content originates from the outsider-controlled tool response payloads (i.e., tool outputs are not authored by the operating user).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata