use-dom
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill documentation (see "iframes or embeds — Embedding external content that requires a browser context" and the "Exposing Native Actions to the Webview" section in SKILL.md) explicitly supports loading external web content into a DOM/webview and shows that that content can call native async functions (e.g., showAlert, saveData), meaning untrusted third‑party pages could supply instructions that materially influence app behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata