antv-l7

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's references include multiple explicit runtime examples that fetch and ingest public third‑party content (e.g., references/data/source-geojson.md uses fetch('https://gw.alipayobjects.com/...json'), references/data/source-mvt.md and references/core/scene-methods.md show getCustomData/Scene.addProtocol custom fetch handlers), and those fetched JSON/CSV/MVT/HTML payloads are parsed and fed into layer.setData, .source(...) and Popup.setHTML calls so external, untrusted content can directly influence rendering and runtime behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 11:25 AM