editor-gui
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The EFWorkbench's Agent Sync panel (ef-agent-panel) explicitly accumulates ef-edit events and builds copyable agent prompts from event.detail (including elementHtml/selector) — i.e., it ingests DOM/media content produced or provided by users/third parties (see "Agent Panel & ef-edit Event System" and EFAgentPanel/editEvents files), which can directly influence generated prompts and downstream agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata