ai-pm
Warn
Audited by Snyk on Aug 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md 的 Step 2 透過
mcp-figma解析使用者提供的「Figma 連結」並提取頁面/Frame/文案/Label 等可讀文字,屬於在運行流程中攝取外部(使用者提交)自由文本的間接提示注入風險。
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill requires a Figma link as a mandatory runtime input and explicitly calls
mcp-figmato parse that remote design, so fetched Figma content (e.g. https://www.figma.com/file/AbCdEf/insurance-portal?node-id=123:456) will directly control the agent's generated spec output.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata