sn-image-imitate

Warn

Audited by Snyk on May 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly accepts a reference_image as a local path or URL and (per SKILL.md Step 1 and the Worker Agent workflow) calls sn-image-recognize on that image (and later uses the VLM review outputs from prompts/layout_review.md) to extract long captions, layout blueprints and fix_hints which are then used to rewrite prompts and drive generation—meaning arbitrary user-provided or public-image content fetched from URLs is ingested and directly influences agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 1, 2026, 09:00 AM
Issues
1