globe-particles

Warn

Audited by Snyk on Aug 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow ingests outsider-authored free text because the demo HTML (embedded via frame.srcdoc in demo/index.html) contains an attacker-controlled payload string (encodedHtml) that is base64-decoded at runtime and assigned as srcdoc, after which it reads/modifies DOM and processes inner HTML/text content.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The demo loads and injects these runtime script files into the iframe at runtime (via the runtimeFiles array and runtimeSources), which will fetch and execute the JavaScript: "../../../../assets/runtime/runtime-027051effa47-gsap-min.js", "../../../../assets/runtime/runtime-163ebd087cfc-iconify-icon-min.js", "../../../../assets/runtime/runtime-25023b521d77-three-min.js", "../../../../assets/runtime/runtime-689ca8dda44c-scrolltrigger-min.js", "../../../../assets/runtime/runtime-ccc8894b3418-runtime.js".

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 16, 2026, 07:34 AM
Issues
2
Security Audit — snyk — globe-particles