generate-minecraft-3D-build-plan
Warn
Audited by Snyk on Mar 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The CLI and scripts (scripts/generate_minecraft_build_plan.py and .ts) accept arbitrary --images HTTP/HTTPS URLs and include them in the JSON payload sent to https://agent.deepnlp.org/agent_router, so untrusted third-party image content is ingested and can influence the Craftsman agent's outputs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata