syncfusion-blazor-maps
Warn
Audited by Snyk on May 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly loads external tiles and GeoJSON via MapsLayer UrlTemplate/ShapeData and lists public providers (tile.openstreetmap.org, maps.googleapis.com, dev.virtualearth.net, atlas.microsoft.com, cdn.syncfusion.com), meaning the skill consumes/displayes untrusted third‑party content at runtime that could contain instruction‑like text and materially influence agent behavior if forwarded to an automated system.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata