github-repo-cards
Warn
Audited by Snyk on Jun 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Outsider-authored free text from public GitHub pages/APIs is ingested at runtime and embedded into the SVG/LLM-readable strings (e.g.,
gh_trending_card.pyscrapeshttps://github.com/trendingand uses the scraped repo description text;gh_repo_card.pyfetches repo descriptions/homepages and contributor logins/avatars from GitHub), which then become readable prose in the generated SVG.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata