dapp-builder
Warn
Audited by Snyk on Apr 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow (SKILL.md and references/ui-patterns.md) explicitly instructs the agent/UI to connect to the public Freenet network, "subscribe_to_contract" and deserialize/handle GetResponse and UpdateNotification from contracts that run on untrusted peers, meaning arbitrary third-party (user-generated) state is fetched and directly influences app/agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata