neta-developer

Warn

Audited by Snyk on May 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill's demo SPA explicitly fetches and displays user-generated content from the public Neta API (api.talesofai.com) — e.g., GenerateAPI.listArtifacts and GenerateAPI.getArtifactDetails in assets/demo-spa/api.js which app.js's openArtifactModal shows (including artifact input/prompt) and SKILL.md's core workflow directs calling platform APIs — meaning untrusted third‑party content is ingested and can be reused to influence subsequent actions or prompts.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 5, 2026, 06:39 AM
Issues
1
Security Audit — snyk — neta-developer