banner-creator
Warn
Audited by Snyk on May 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill downloads arbitrary reference images from user-supplied HTTP(S) URLs via download_reference_image (scripts/banner_creator.py) and then passes the image into client.models.generate_content in generate_banner, so untrusted third-party content from the open web is ingested and can materially influence the model's outputs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata