light-frontend-design
Fail
Audited by Snyk on Jul 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). Several listed URLs point to third‑party "Claude" plugin/skill marketplaces and untrusted skill-hosting subdomains (claudepluginhub.com, claudemarketplaces.com, skills.* and similar) that can distribute arbitrary code or installers and are therefore suspicious, while the other links (official docs, well-known CDNs, npm, and mainstream GitHub repos) look benign.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md:13-14 requires “先 web 搜索核实涉及的具名产品/品牌”,which at runtime can fetch public web pages and ingest their free-form text into the agent’s LLM context (public web content category).
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata