dribbble-reference-harvester
Warn
Audited by Snyk on Jun 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow runs
./skills/.../scripts/collect.sh, which invokesnode ./src/cli.mjs "$@"; this skill’s purpose is to “gather visual references from Dribbble,” so at runtime it will fetch Dribbble (public web content) and ingest the resulting page/text/metadata into the agent’s LLM context via the CLI’s processing.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata