create-svg
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). At runtime the CLI
render/verifypipeline ingests user-provided YAML scene text (viaload_scene()->yaml.safe_load-> Pydantic), which is then rendered into SVG and optionally checked in Chromium, so outsider-authored free text can reach the LLM-exposed pipeline.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata