picasso

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill accepts arbitrary external image URLs via the "--edit " option (and references browsing external model pages like https://fal.ai/models and APIs), meaning it fetches and processes untrusted third‑party content provided from the open web as part of its workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 09:51 AM