image-gen

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly lists web-fetch/search tools (agents/image-prompter.md: tools: Read, Glob, Grep, WebFetch) and SKILL.md includes a code example and known-issue note showing use of the Google Search tool to pass public web search results into image generation, so the agent can fetch and interpret untrusted public web content that may influence generation decisions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 03:49 AM