moai-workflow-design-import
Warn
Audited by Snyk on Apr 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly ingests untrusted user-generated design content: Path A parses external Claude Design ZIP/HTML handoff bundles (including inline JSON/script blocks) and Path B1 invokes the meta-harness to generate a Figma extractor that fetches Figma files (third‑party user content), both of which are parsed and used to produce tokens/components that materially influence downstream actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata