ui-audit
Warn
Audited by Snyk on Mar 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The README usage examples ("Audit this design: [figma-url]" and "Review this landing page for accessibility issues") together with SKILL.md's audit output fields "figma_url" and "screenshot_url" show the skill expects the agent to accept and process arbitrary external URLs/screenshots (public Figma pages or landing pages), i.e., untrusted third‑party content the agent would read and use to drive audit decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata