pilot-service-agents-climate

Warn

Audited by Snyk on Jun 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). At runtime the user can trigger /help, /summary, or free-text /data queries via pilotctl --json send-message <hostname> --data ..., and the agent’s response is read from pilotctl --json inbox where the agent may include upstream-fetched public web content (e.g., Electricity Maps/Open-Meteo/other external sources) as readable text in the LLM context, creating an indirect prompt-injection path.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 23, 2026, 01:56 AM
Issues
1
Security Audit — snyk — pilot-service-agents-climate