html-to-interaction-prompts
Warn
Audited by Snyk on Jul 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). High chance of outsider prompt injection because the workflow instructs the agent to “Inspect the real source first” by reading the provided HTML/CSS/scripts (Step 1, SKILL.md:42-44), and any outsider-authored HTML (e.g., downloaded/exported page or live-site HTML/content) can contain free-text/script content that the agent may ingest into the LLM context during inspection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata