datocms-frontend-integrations
Warn
Audited by Snyk on May 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs the agent to query and subscribe to DatoCMS public content (e.g., executeQuery using @datocms/cda-client, QueryListener in references/astro-realtime.md, and the Web Previews preview-links webhook in references/astro.md), which ingests user/editor-generated content (including stega metadata) that the runtime interprets and uses to drive actions like click-to-edit overlays, navigation, and reloads.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata