ui-audit

Warn

Audited by Snyk on Jun 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). Skill runtime path: it instructs the agent to render a user-supplied Live URL / fetch pages and then run scripts/ui_checks.js in the browser, which reads arbitrary outsider-authored page text/DOM (including any third-party content on that page) into the LLM context via the returned JSON leads (e.g., rawI18nKeys, technicalGarbage, overflowingText, lowContrastText).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 23, 2026, 07:09 PM
Issues
1
Security Audit — snyk — ui-audit