find-icon
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The skill’s runtime workflow uses
gh apito fetch SVGs (and thus readable text/markup) from multiple outsider-authored public GitHub repositories/direct registries likelucide-icons/lucide,lobehub/lobe-icons,pheralb/svgl, andsimple-icons/simple-icons, and then extracts/parses their SVG path data into the agent’s working context (step 5/5-6 in SKILL.md).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata