design-critique

Warn

Audited by Snyk on Aug 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md는 URL 입력 시에 “WebFetch로 HTML/CSS 수집”을 수행하므로, outsider-authored 웹페이지 텍스트가 런타임에 LLM으로 읽히는 경로가 존재합니다(단, 인증 필요/JS shell이면 스크린샷 요청한다고도 명시).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 01:30 PM
Issues
1
Security Audit — snyk — design-critique