live-dev-config
Warn
Audited by Snyk on Aug 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Required workflow step 2.1 launches
resources/credential-form.js, which serves a local 127.0.0.1 HTML form that ingests user-provided free text and then writes it into.env.localfor later piping into Vercel/GitHub CLI commands.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata