lov-find-logo
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/find_logo.py, the runtime pathhttp_get()→scrape_page_images(https://{domain}/)parses attacker-influencedog:image/<link rel="icon">values from the outsider-author provided brand homepage (derived from user-supplied--url), so the LLM ingests free text/HTML sourced from external parties at runtime without selecting a specific pre-verified item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata