figma-code-to-canvas
Warn
Audited by Snyk on Jul 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The workflow ingests outsider-provided free text via the user-supplied “Source URL/app” (Step 15) and especially the
capture-publicmode that converts an arbitrary public URL into Figma layers (Step 8), which can include attacker-authored prompt-injection content read during capture.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata