canvas-theme
Warn
Audited by Snyk on Jul 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). At runtime, the skill’s workflow reads the target canvas’s existing shape text via the tldraw bridge/tooling:
api.getFocusedDoc/api.getShapespulls the current document’s shape records (including user-authored text), which are then placed into the agent’s prompt context for “current vs. target style” comparison and reporting.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata