canvas-populate

Warn

Audited by Snyk on Apr 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). This skill explicitly fetches arbitrary HTTP(S) URLs in the "add image" flow (downloads with curl and derives filenames/slugs from the URL) and accepts arbitrary URLs in "add link" (which fetches Open Graph previews), so untrusted third‑party web content is ingested and can influence node IDs, sizing/positioning, and subsequent matching/behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 10, 2026, 05:07 PM
Issues
1