html-to-breakdance

Warn

Audited by Snyk on Aug 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In Step 4 (Modes A/B/C), the runtime accepts user-provided HTML directly from the conversation or fetches it from a user-supplied URL (WebFetch//browse), and Step 5 then calls respira_convert_html_to_builder with that HTML/CSS read text—so outsider-authored free text is ingested by the LLM/tooling as raw input.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 01:28 AM
Issues
1
Security Audit — snyk — html-to-breakdance