ui-scanner
Warn
Audited by Snyk on Aug 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the runtime workflow “URL input → page crawl → … style extraction”, the agent must fetch and read arbitrary web page HTML/CSS from the outsider-supplied website URL (via
web_fetch), which can include free text that the LLM ingests while extracting visual/design information.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata