image-gen-skill

Warn

Audited by Snyk on Aug 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该技能在运行时会将用户/外部输入的 prompt(由生成意图对应的文本经 API generateImage 传入)直接送入云函数 image-gen-handlerhandleGenerateImage,并由 ai/image.js 调用 imageModel.generateImage 使用该 free text 进行生成。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 17, 2026, 04:58 AM
Issues
1
Security Audit — snyk — image-gen-skill