frameio
Warn
Audited by Snyk on May 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). This skill uses Membrane to fetch and act on Frame.io content (see SKILL.md "Popular actions" like List Comments / Get Asset and "Running actions"), meaning the agent will read and interpret user-generated third-party assets/comments/review links from Frame.io—which could contain untrusted instructions that influence subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata