grapesjs-studio-sdk

Warn

Audited by Snyk on Mar 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly shows runtime ingestion of public third‑party content (e.g., Asset Providers in rules/configuration/assets/asset-providers.md that fetch from external APIs like https://picsum.photos and the component example that fetches from https://dummyjson.com/products) and then reads and renders that data into the editor UI/workflow, which meets criteria for untrusted user‑generated content that can influence actions and tool behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 20, 2026, 01:38 PM
Issues
1