craftsman-agent-build-plans
Warn
Audited by Snyk on Mar 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's SKILL.md and the scripts (e.g., scripts/generate_lego_build_plan.py and .ts) POST user prompts and user-supplied ref_image_url values to the external OneKey Gateway at https://agent.deepnlp.org/agent, meaning the agent ingests untrusted third-party content (arbitrary URLs and API responses) that can materially influence generation and downstream actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata