ue5-network-viz
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). UE5 MCP “execute_tool_script” is used to run UE-side Python that embeds and renders label text from the topology payload (including
spec["label"]/spec["text"]), and that payload ultimately originates from outsider-provided device/interface/link fields such as hostnames, labels, and down-interface summaries.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata