number-details
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The skill’s demo runtime loads and renders first-party HTML that contains free-text content (e.g., the “Cedar Lodges | Where the Mountains Breathe” headings/body copy) into a sandboxed iframe via
srcdoc, meaning any outsider-supplied variant of that HTML would become LLM-reachable text only if the service/skill incorporates it into theencodedHtmlpayload.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata