sf-b2c-controllers
Warn
Audited by Snyk on Mar 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly requires the agent to "Fetch live documentation FIRST" from public sources such as web searches and the GitHub repo github.com/SalesforceCommerceCloud/storefront-reference-architecture and the Salesforce B2C Commerce API reference, which the agent must read and use to decide implementation details—allowing untrusted third‑party content to influence its actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata