datocms-frontend-integrations

Warn

Audited by Snyk on May 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to query and subscribe to DatoCMS public content (e.g., executeQuery using @datocms/cda-client, QueryListener in references/astro-realtime.md, and the Web Previews preview-links webhook in references/astro.md), which ingests user/editor-generated content (including stega metadata) that the runtime interprets and uses to drive actions like click-to-edit overlays, navigation, and reloads.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 6, 2026, 05:34 AM
Issues
1