narova-google
Warn
Audited by Snyk on Aug 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In both
tool/worker.py(TTS) andtool/video-worker.py(Veo), the required runtimemain()reads JSONL requests fromsys.stdinand then LLM-ingests outsider-provided free text fields (textorprompt) when an external user submits a synthesis/generation request via the Narova provider protocol.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata