ui-creator

Warn

Audited by Snyk on Mar 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's workflows and example commands (e.g., Workflow 2 and Playwright usage in SKILL.md: "npx tsx scripts/evaluate-ui.ts https://example.com/page" and "npx tsx scripts/compare-variations.ts ") explicitly fetch and analyze arbitrary public URLs with Playwright, meaning untrusted, user-provided third-party webpages are ingested and used to drive evaluation, recommendations, and next actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 03:27 PM
Issues
1