dmc-py

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill documentation explicitly shows fetching and ingesting open third-party content (e.g., loading CDN scripts via external_scripts in references/date-pickers-guide.md and async fetch(url) clientside examples and server-side requests.get(url) in references/callbacks-advanced.md), where the fetched, potentially untrusted data/JS is parsed and used to update UI and drive callbacks—so external content can materially influence app behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 10:02 AM