design
Warn
Audited by Snyk on Mar 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). This skill explicitly ingests external, user-controlled content (e.g., capturing live websites via
/site-to-figma, converting/reading arbitrary Figma URLs with/figma <URL>, and reviewing preview servers or HTML via/design-review), which are open/public or user-generated sources the agent is expected to read and that can materially influence subsequent tool actions and decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata