blueprint
Warn
Audited by Snyk on Aug 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The outsider-authored free text exposure occurs because, in project mode, a user-run flow selection leads fan-out where each “scenario-prompt.md” agent reads and emits repo text (via
source_paths) that is then rendered into HTML attributes includingdetailfields and message labels/captions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata