storybook-pentest
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Required runtime workflow renders and enumerates the target Storybook via
GET <origin>/index.jsonand then drivesiframe.html?id=<story-id>&...(including executingplay-fnand typing stress payloads), so outsider-authored free text in story props/play functions is ingested by the LLM/agent at runtime as part of evaluating and reporting.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata