gpt-engineer
Warn
Audited by Snyk on Aug 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/run_codex_agent.py, the runner reads the outsider-provided--prompt-filecontents orsys.stdin(user text) and concatenates it intodelegated_prompt, which is then sent to the Codex delegate process viastdin(process.communicate(input=delegated_prompt, ...)).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata