story-metrics-screenshot-parser

Warn

Audited by Snyk on Feb 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's required workflow asks users to paste raw text transcriptions of Story insights from public social platforms or third-party analytics tools (see "Information Gathering → Required Inputs" and the line referencing Instagram/TikTok and third-party tools), so the agent ingests untrusted, user-generated content from open web sources and must interpret it to decide platform/fields and populate outputs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 22, 2026, 05:56 PM