photoreal
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Skill “photoreal”는 build_prompt.py에서 사용자 입력인
--subject및(--scene custom일 때)--situation을 그대로 프롬프트 텍스트로 조립해 LLM(이미지 생성 프롬프트)에 전달하므로, outsider가 해당 입력 경로에 자유 텍스트를 넣으면 런타임에 LLM이 읽는 텍스트가 된다(포스트/큐/피드 같은 외부 콘텐츠 강제 수집은 아님).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata