studioai-product-photoshoot

Warn

Audited by Snyk on May 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly accepts source images "reachable via https://" (SKILL.md) and passes those sourceImageUrls into generate_image while the prompt-builder/enhancer (references/modes.md and SKILL.md steps 3–4) analyzes the image (pose, colors, etc.), so arbitrary public URLs or user-uploaded images can be ingested and materially influence generation prompts and subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 6, 2026, 12:15 PM
Issues
1
Security Audit — snyk — studioai-product-photoshoot