brand-extract

Warn

Audited by Snyk on Jun 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). The skill’s runtime path renders brand.html from a JSON payload (__OD_BRAND_PAYLOAD__) that is populated from the measured target website (outsider-authored page content such as logo/imagery URLs and extracted text like voice/tagline), and that payload is parsed and inserted into the LLM context via the agent’s own extraction/synthesis loop (i.e., untrusted outsider text can be fed back into the agent for further generation).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 30, 2026, 10:28 PM
Issues
1
Security Audit — snyk — brand-extract