play-store-app-install
Warn
Audited by Snyk on Aug 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In play-store-app-install, the runtime path
scripts/playapp.py resolve/preflight/status/open-listing/wait-installed/launchreads only the outsider-provided ref string (Play URL or bare package name) to extract/validate?id=and to build on-device intents, and it never fetches/reads arbitrary web content or third-party text sources.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata