social-fetch
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
social-fetch, the runtime workflow accepts a user-provided URL, detects the platform, and then fetches and ingests that outsider-authored post text via per-platform network strategies (e.g., Reddit"<url>.json"or X/LinkedIn/Instagram/TikTok/Threads via rendered preview/open-graph), so attacker-controlled content can be processed without selecting a specific pre-vetted item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata