moai-workflow-design-import

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly ingests untrusted user-generated design content: Path A parses external Claude Design ZIP/HTML handoff bundles (including inline JSON/script blocks) and Path B1 invokes the meta-harness to generate a Figma extractor that fetches Figma files (third‑party user content), both of which are parsed and used to produce tokens/components that materially influence downstream actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 12:18 AM
Issues
1