html-to-bricks
Warn
Audited by Snyk on Aug 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Step 4 (Mode A pasted in the conversation) and Step 4 (Mode B URL fetch) the workflow accepts outsider-authored HTML/CSS (including inline
<style>and external stylesheet text) and then Step 5 callsrespira_convert_html_to_builderwith that HTML/CSS at runtime, so the LLM ingests attacker-controlled free text for conversion.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata