generate-markdown

Warn

Audited by Snyk on Jul 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Required runtime workflow fetches Sanity documents from a project/dataset via the Sanity MCP connector (get_document/query_documents and internal link resolution), then verbatim-transcribes outsider-controlled Portable Text fields into markdown.code, so free text authored by provider users can be ingested.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 09:59 AM
Issues
1
Security Audit — snyk — generate-markdown