brand-identity
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The
brand-identityskill’s runtime workflow invokes./scripts/verify.shwhich reads a user-provided/selecteddesign-tokens.jsonfile from a project path (JSON free text content) and ingests its color tokens and$extensions["com.risco.contrast"]pairs to compute contrast, so outsider-authored tokens can be fed directly into the runtime validation logic.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata