stable-diffusion-image-generation

Warn

Audited by Snyk on Mar 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). Yes — SKILL.md instructs the agent to load models and adapters directly from the public Hugging Face Model Hub (e.g., DiffusionPipeline.from_pretrained(...) and specific user models like "lllyasviel/control_v11p_sd15_canny" and "h94/IP-Adapter"), which are open, user-contributed artifacts that the agent will fetch and use at runtime and can materially change its behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 28, 2026, 06:09 PM
Issues
1