courseware-builder
Warn
Audited by Snyk on Aug 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow only ingests the outsider’s submitted course topic/outline during Phase 1/2 and then embeds it into the generated HTML/JS
STEPScontent (rendered viarender()usingstep.title,step.desc,step.points[].text, andstep.code).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata