design-distill
Warn
Audited by Snyk on Jul 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Yes—during the
/design-distill <refs>workflow it usesagent-browserto open runtime reference URLs/pages (outsider-sourced) and extracts readabledocument.title/computed style text viaagent-browser eval, which is then fed into the agent’s LLM context for the Claude Design prompt + moodboard synthesis.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata