editorial-portrait-composition
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow reads
references/cases.mdon every invocation and ingests the case cards’ free-text prompt excerpts/summaries (including links like original sources), which are outsider-authored content within the file being read.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The Skill requires inspecting anchor Cases listed in references/cases.md and those Case entries contain external media/evidence links (e.g., https://cms-assets.youmind.com/media/1785143493732_xu4dij_HOKmtpTaYAAP1_0.jpg and https://goodcase.ai/cases/3d-cg-c35a17fc041c) that the agent would fetch at runtime and use to directly inform prompts, so this is a runtime external dependency controlling prompt content.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata