unity-pico-design
Warn
Audited by Snyk on Aug 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SECUREMR/渲染管线在运行时会读取来自 SecureMR pipeline 的文本张量(如 RenderTextOperator 的
textoperand)并将其打印/渲染,而该文本张量可由非可信外部输入(如运行时加载的 glTF/模型/自定义 tensor、或通过应用侧管道写入的任意 operand)影响,因此存在间接提示注入暴露。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata