mural

Warn

Audited by Snyk on Jul 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The Mural skill ingests outsider-authored free text at runtime by fetching widget content from the Mural REST API (e.g., sticky-note/textbox/widget “text” fields) and returning it via CLI/JSON output, which is explicitly treated as untrusted user content (from other users’ Mural boards/widgets).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 08:30 PM
Issues
1
Security Audit — snyk — mural