facebook-marketplace-message-sender
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Facebook Marketplace message sending runs at runtime by navigating to attacker-provided
thread_url/listing_urland reading page DOM text (including any outsider-authored chat/inbox content) vianew_tab(THREAD_URL)and subsequentjs(...)scans likedocument.body.innerText/textContentduring composer verification and post-send confirmation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata