light-frontend-design

Fail

Audited by Snyk on Jul 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). Several listed URLs point to third‑party "Claude" plugin/skill marketplaces and untrusted skill-hosting subdomains (claudepluginhub.com, claudemarketplaces.com, skills.* and similar) that can distribute arbitrary code or installers and are therefore suspicious, while the other links (official docs, well-known CDNs, npm, and mainstream GitHub repos) look benign.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). SKILL.md:13-14 requires “先 web 搜索核实涉及的具名产品/品牌”,which at runtime can fetch public web pages and ingest their free-form text into the agent’s LLM context (public web content category).

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 17, 2026, 01:44 AM
Issues
2
Security Audit — snyk — light-frontend-design