krea-build
Warn
Audited by Snyk on May 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill accepts and validates user-provided image URLs and explicitly recommends HEAD-checking and uploading remote assets (see references/validation.md and the generateImage signatures in references/api-client.md), which means the agent will fetch and interpret arbitrary external http(s) URLs supplied by users and those third-party contents can influence generation behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata