promo-video

Warn

Audited by Snyk on Apr 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's required workflow performs automated brand discovery on arbitrary repositories (scripts/discover-brand.ts — it reads README, extracts URLs, copies logos and may inline SVG via dangerouslySetInnerHTML) and calls external ElevenLabs APIs (scripts/discover-voices.ts, scripts/generate-voiceover.ts), and SKILL.md instructs using those discovered/remote contents to pre-populate prompts and drive voice/video generation, so untrusted third‑party/user-provided content can influence agent decisions and tool use.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 5, 2026, 06:54 PM
Issues
1
Security Audit — snyk — promo-video