ui-clone

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly scrapes and screenshots public PageFlows pages (pageflows.com) via pageflows_capture.py (using agent-browser + eval/SCREENS_JS) and then reads those untrusted, user-generated screenshots/URLs into the build/visual_diff workflow (references/capture.md and references/build.md), so external PageFlows content is ingested and directly influences tooling and implementation decisions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 01:20 AM