baoyu-electron-extract

Warn

Audited by Snyk on Jun 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). Outsider-authored free text is ingested from the target Electron app’s bundled app.asar contents at runtime—specifically .js.map files’ sourcesContent (and any embedded source text) are read and written into restored/, and that restored prose is then passed to the agent’s LLM context indirectly via the skill’s output files (e.g., the user will read/quote the extracted/restored source).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 17, 2026, 02:18 AM
Issues
1
Security Audit — snyk — baoyu-electron-extract