WhisperX tag archive

#expertise-api

This page collects WhisperX intelligence signals tagged #expertise-api. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-28 15:54:11 · GitHub Issues

1. Live Prompt Injection via Hardcoded expertise-api Endpoint Exposes Claude Code, Copilot Users

A critical security vulnerability in the expertise pipeline exposes users to session-scoped prompt injection. The `UserPromptSubmit` hook (`hooks/expertise-preflight.sh`) automatically calls `${EXPERTISE_API_URL}/expertise/search` on every prompt submission and injects the API response into the `systemMessage` field, w...