visual-brand-extractor

Warn

Audited by Snyk on Mar 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's Phase 1 "Fetch Target Pages" and Inputs require using WebFetch to read arbitrary public website URLs (homepage/product/blog) provided by the user, and the agent directly ingests and interprets that untrusted page content to determine colors, fonts, and other actions—creating a clear avenue for indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 05:17 PM
Issues
1