alibabacloud-tech-solution-animation-creation-auto-deploy

Warn

Audited by Snyk on Apr 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill calls the public devsapp.net service from scripts/create-custom-domain.sh (curl POSTs to https://domain.devsapp.net/token and https://domain.devsapp.net/domain), parses the JSON responses, and directly uses the returned token/response to construct helper function names and drive DNS registration and FC custom-domain creation, so untrusted third-party content can materially influence tool actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 17, 2026, 10:30 AM
Issues
1