create-figure

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill ingests and acts on untrusted, user-supplied content — e.g., analysis.generate_from_assess reads arbitrary assess JSON to drive figure generation (analysis.py) and the Walkthrough explicitly reports that figure_lab's "promote" copies arbitrary HTML without validation and D3 templates accept window.INJECTED_DATA (d3/gallery and wrap_d3_canvas), meaning third-party/user-generated content can influence rendering and downstream tool actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Issues
1
Security Audit — snyk — create-figure