alterlab-modal
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's main workflow examples explicitly fetch and execute open third‑party content — e.g., git clone in references/images.md, Image.run_function and download_model using diffusers/transformers.from_pretrained in references/images.md and references/examples.md, Image.from_registry (Docker Hub/ghcr) pulls, and requests.get to external APIs in references/examples.md — all of which are public, potentially user‑generated sources that the agent ingests and runs, allowing indirect prompt/code injection to influence behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata