design-qa-review-skill
Warn
Audited by Snyk on Jun 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The skill’s REQUIRED runtime workflow can ingest outsider-authored free text when it performs URL-based page analysis (e.g.,
--page-url/pageUrl), since it may fetch arbitrary public/staging pages and then use their readable content (DOM/text) as LLM context for analysis/reporting, enabling indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata