motion-meaning
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/verify-reduced.mjs, the runtime opens user-supplied local HTML/fixture pages viapage.goto()and reads free text only indirectly throughwindow.__mm/window.__readyset by that HTML, so an outsider can author the HTML and have it executed/inspected by the verifier.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata