sketch
Warn
Audited by Snyk on May 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly supports grounding via Google Image Search ("Enable via
google_searchtool config" in references/api-integration.md) and accepts external reference images / existing asset URLs for style-transfer (references/style-transfer.md and the SKILL.md capabilities), meaning the agent will fetch and interpret public third‑party images/URLs as part of its workflow and those external contents could materially influence prompt construction and subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata