globe-particles

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The runtime JS in demo/index.html decodes and injects a base64-encoded HTML payload into a sandboxed iframe (frame.srcdoc), where the attacker-controlled “encodedHtml” content is parsed/executed from outsider-authored text at runtime (indirect prompt injection surface via embedded HTML/JS).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 01:38 PM
Issues
1
Security Audit — snyk — globe-particles