canva-brand-check
Warn
Audited by Snyk on Jun 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The workflow calls
Canva:list-brand-kitsandCanva:get-design-thumbnail/Canva:get-design-contentto ingest brand-kit and design text/imagery at runtime; these are outsider-authored (public/third-party Canva content and brand-kit assets not authored by the operating user) and become LLM-readable context via the connector payloads.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata