openbb-app-builder

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's Reference mode (SKILL.md Phase 1) and the APP-INTERVIEW.md "Reference Example Analysis" explicitly instruct the agent to ingest and analyze third‑party code/URLs (e.g., GitHub, Streamlit Cloud, HuggingFace Spaces) and source URLs / web‑scraping targets, meaning untrusted external content is fetched and interpreted as part of the workflow.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 07:34 PM
Issues
1