xiao-esp32s3
Warn
Audited by Snyk on Jul 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime workflow runs
scripts\read_serial.ps1, which reads arbitrary free-form serial output from the connected board (Write-Output $p.ReadLine()), and that text is then ingested into the agent/LLM context via the tool’s output/log stream; this serial content is effectively outsider-authored (comes from an external device/person-controlled firmware), enabling indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata