syncfusion-javascript-dropdowns
Warn
Audited by Snyk on May 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's main documentation and examples (e.g., references/dropdownlist-data-binding.md, references/dropdownlist-filtering.md, and references/multiselect-data-binding/cascading examples) explicitly show using DataManager with remote URLs (for example https://services.odata.org/... and placeholders for arbitrary API endpoints) and event handlers (actionComplete/filtering/change) that fetch, bind, modify, and drive component behavior from those remote public sources, so untrusted third-party content would be ingested and could materially influence subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata