multi-chart-draw

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill explicitly embeds and communicates with external web editors (e.g., the iframe to https://embed.diagrams.net in assets/architecture.html and charts-output/ai_chat_architecture.html) and states it uses the GeoGebra Materials API in the README, which are public/third‑party (potentially user‑generated) sources that the skill's runtime exchanges messages with and can ingest (e.g., receiving XML via postMessage or fetching materials), so untrusted content can influence processing or subsequent actions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 07:37 AM