design-critique
Warn
Audited by Snyk on Aug 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). SKILL.md requires the agent to ingest only first-party vendor-authored UI details from an already-provided screenshot/URL (user content) and optionally to fetch trusted Checklist Design checklists from
https://www.checklist.design/api/...; there is no runtime path that reads outsider-authored free text from a queue/feed, tickets, or other continuously user-submitted sources without first selecting an item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata