alova-api-module
Warn
Audited by Snyk on Feb 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The alova.config.ts explicitly specifies an input URL ('https://api.example.com/openapi.json') for OpenAPI auto-generation, so the tool is expected to fetch and parse external OpenAPI JSON from third‑party sites as part of its workflow, exposing the agent to untrusted third‑party content.
Audit Metadata