flomo-memo-to-markdown

Warn

Audited by Snyk on Aug 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The required runtime workflow reads memo text (raw_memo.get("content")) from the user’s local flomo desktop/API state (including HTML in plain_text = ... html_to_markdown(content_html)) and converts it into Markdown, so outsider-authored free text is ingested indirectly via the user’s flomo memos.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 02:08 PM
Issues
1
Security Audit — snyk — flomo-memo-to-markdown