claude-usage
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md/scripts/usage_summary.py read and parse a session’s local
.jsonlfile viaprojects_dir.rglob("*.jsonl")andfile_path.read_text(...), so any free text placed into that JSONL by an outsider becomes runtime-ingested content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata