claude-video-promo
Warn
Audited by Snyk on May 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly searches and downloads public stock from third-party APIs (Pixabay/Pexels via scripts/stock_search.py and scripts/stock_download.py), analyzes the downloaded video frames (scripts/analyze_contrast.py) and feeds that untrusted, user-generated content (and preview URLs) into the Remotion pipeline (AdaptiveText/useContrast) which directly influences rendering decisions and tool actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata