codex-doctor

Warn

Audited by Snyk on Jul 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). Runtime path python3 <skill-dir>/scripts/scan_workspace.py --cwd "$PWD" --compact-json ingests and emits AGENTS*.md, SKILL.md, and hooks.json/config.toml body text from the current repository into the scanner’s JSON output, and that output is then used by the agent—these are outsider-authored repository documents if the repo contains contributions from parties other than the operating user.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 01:31 AM
Issues
1
Security Audit — snyk — codex-doctor