pihole-blocklist
Warn
Audited by Snyk on Jul 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow is to evaluate a user-provided Pi-hole blocklist source (URL) and apply domain rules, which at runtime typically involves fetching/reading outsider-authored free-form list content from that URL into the LLM context for analysis—an indirect prompt-injection path from public web content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata