sap-extension-creator
Warn
Audited by Snyk on Aug 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the extension frontend
index.html, the WebSocket handler callsrender(d.data.messages)onmessages_update/broadcast_messageswithout selecting any specific item first, so user-supplied chat text can be ingested as free text at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata