promo-video
Warn
Audited by Snyk on Apr 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's required workflow performs automated brand discovery on arbitrary repositories (scripts/discover-brand.ts — it reads README, extracts URLs, copies logos and may inline SVG via dangerouslySetInnerHTML) and calls external ElevenLabs APIs (scripts/discover-voices.ts, scripts/generate-voiceover.ts), and SKILL.md instructs using those discovered/remote contents to pre-populate prompts and drive voice/video generation, so untrusted third‑party/user-provided content can influence agent decisions and tool use.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata