nostr-comments
Warn
Audited by Snyk on Jun 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Outsider-authored free text can enter the LLM context via Nostr comment/event body text fetched at runtime by
useComments/useReplies/useWallComments(kinds 1111/1244/1/0), where other users’ comment content is ingested and then rendered/processed by the agent’s LLM pipeline.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata