spline-3d-integration

Warn

Audited by Snyk on Mar 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly embeds and loads user-created Spline scenes from public prod.spline.design URLs (see SKILL.md Step 2 and numerous guides/examples such as Spline scene="https://prod.spline.design/.../scene.splinecode", spline.load(sceneUrl), and the preload href), so it fetches untrusted, third‑party user-generated content that the runtime API reads and reacts to (events, variables, object data) and can therefore influence app behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 7, 2026, 05:35 PM