ffc-dev

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs commands to call the Frappe API via internal/client/client.go (e.g., client.New(cfg) and endpoints like /api/resource/{DocType} and /api/method/...) using config or env vars (FFC_URL, --site, etc.), meaning the agent will fetch and parse responses from arbitrary third-party Frappe sites (untrusted/user-provided) and use those responses to drive output and behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 12:14 PM
Issues
1