create-brand-kit
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Phase 0 the skill performs “WebFetch for copy and positioning” and “WebSearch” on the user-provided company site/starting point, then the extracted “verbatim headline copy” and other mined text are written into
brand/BRIEF.mdfor downstream designer/critic agents to read, making outsider-authored free text ingested at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata