rn-cover-skill
Warn
Audited by Snyk on Jul 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In RN Cover Skill’s runtime workflow, outsider-provided inputs (
labelandtitle) are inserted directly into the LLM’s composed prompt/config for built-in ImageGen (via the{theme}/prompt assembly) and then used for SVG text viascripts/compose_cover.py, so the agent ingests free text before any “specific item” selection step.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata