virtual-agent/ios
Warn
Audited by Snyk on May 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime workflow loads a campaign URL into
WKWebViewand injects/bridges with that page’s JavaScript, so any free-form text content authored by an outsider on that remote campaign page can be read/processed by the agent via the webview/JS message bridge (indirect prompt injection risk).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata