modernize-flp-sandbox
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md at runtime ingests outsider-authored free text from the user’s local UI5 project files—specifically it reads legacy HTML and JS under
$APP_ROOT/webapp/test/and$APP_ROOT/webapp/(including parsing externalized and inline config content, plus extracting inline script blocks and scanning code via regex/greps), so the attacker can provide poison by modifying those files before invoking the skill.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata