frevana-solution-page
Fail
Audited by Snyk on Jul 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). These URLs include a direct .dmg installer link (https://static.frevana.com/app-updates/darwin/universal/Frevana.dmg), which is a high-risk pattern because direct executable installers hosted outside official vendor stores can be used to distribute malware.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow reads
references/design.md(outsider-authored file content) and also uses user-provided natural-language brief fields from the conversation to build prompts/JSON that are then sent to the LLM/image pipeline, so outsider free text can enter the agent’s LLM context via the user brief → internal schema → prompt construction path.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata