ui-creator
Warn
Audited by Snyk on Mar 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's workflows and example commands (e.g., Workflow 2 and Playwright usage in SKILL.md: "npx tsx scripts/evaluate-ui.ts https://example.com/page" and "npx tsx scripts/compare-variations.ts ") explicitly fetch and analyze arbitrary public URLs with Playwright, meaning untrusted, user-provided third-party webpages are ingested and used to drive evaluation, recommendations, and next actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata