maps
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
cmd_search,cmd_nearby(--near) andcmd_area, outsider-provided free-text is sent to first-party HTTP endpoints (Nominatim/Overpass/OSRM/TimeAPI), meaning the agent runtime ingests responses originating from outside the trusted provider and those responses can contain arbitrary place names/hours/addresses that are then returned/used.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata