bridge-analyzer
Warn
Audited by Snyk on Aug 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In scripts/bridge_comparison.py (and similarly bridge_risk_scorer.py/route_optimizer.py/bridge_monitor.py), the runtime fetches untrusted free-form string fields (e.g., bridge
name/displayName) from the external DeFiLlama API endpointhttps://bridges.llama.fi/bridges?includeChains=trueand uses them in matching/output without first selecting a specific pre-known item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata