design-to-code
Warn
Audited by Snyk on Sep 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow ingests arbitrary web pages via URLs and component code/metadata from the public 21st.dev registry (low risk per scoring rules), and uses Google Stitch to process screenshots/URLs/descriptions submitted by the user.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata