syncfusion-angular-mention

Warn

Audited by Snyk on Mar 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill includes multiple required workflows that bind the Mention component to remote DataManager URLs (e.g., references/data-binding.md and templates.md examples using https://services.odata.org/... and https://services.syncfusion.com/... or "https://your-api-endpoint.example.com/api/"), which fetches untrusted/public third‑party data that the component reads and inserts or uses to drive suggestions and selection behavior in the editor—so external content can influence subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 30, 2026, 06:24 PM
Issues
1
Security Audit — snyk — syncfusion-angular-mention