aeo
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/aeo_audit.py, theload()function fetches and parses an outsider-controlled HTTP(S) URL’s HTML (including visible text and embedded JSON-LD) when the runtime workflow is invoked with asourceargument, so attacker-posted free text at that URL can be ingested.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata