frontend-design-subagent
Warn
Audited by Snyk on Apr 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's workflow (SKILL.md "Inspiration" + the Agent Behavior and references/asset-sources.json) explicitly tells the agent to "draw from the provided specific external reference URLs" and to download media from public sources like unDraw and Unsplash, so it may fetch and ingest untrusted, public third‑party content that can materially influence generation and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata