html-to-breakdance
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Step 4 (Modes A/B/C), the runtime accepts user-provided HTML directly from the conversation or fetches it from a user-supplied URL (
WebFetch//browse), and Step 5 then callsrespira_convert_html_to_builderwith that HTML/CSS read text—so outsider-authored free text is ingested by the LLM/tooling as raw input.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata