video-generation
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's workflow and rule files explicitly instruct fetching and parsing remote third‑party assets (e.g., fetch(props.dataUrl) in references/rules/calculate-metadata.md, fetching Lottie JSON in references/rules/lottie.md, and UrlSource/remote image/video use in Mediabunny and images rules), so untrusted external content can be ingested and materially alter composition props and runtime behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata