audiobook-creator
Fail
Audited by Snyk on Jul 18, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). The GitHub releases URL is a personal/third‑party release location used to download unverified binary model files at runtime (high risk), while the ffmpeg.org link is an official documentation page and not suspicious.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Yes: the required Step 1 runs
scripts/extract_text.pyon a user-supplied file path and prints the extracted document text to stdout, which is then ingested by the calling model to buildscript.json(outsider-authored file body text → LLM context).
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata