syncfusion-react-diagram

Warn

Audited by Snyk on Mar 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's documentation and required workflow explicitly describe remote data binding (references/data-binding.md and SKILL.md Data Binding section) — including DataManager URLs and CRUD endpoints (e.g., "https://services.syncfusion.com/.../RemoteData" and crudAction examples) — which causes the agent to fetch and interpret arbitrary public JSON to generate nodes/connectors (via doBinding/setNodeTemplate), so untrusted third‑party content can directly influence diagram construction and subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 25, 2026, 04:26 PM
Issues
1