google-fonts-skill
Warn
Audited by Snyk on Jun 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The skill is a platform “google-fonts” font-selection MCP/plugin; at runtime it likely fetches/reads Google Fonts catalog data (public web content) or other community-provided metadata that becomes LLM-readable text, which is an outsider source via the MCP/plugin’s network retrieval path.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata