ai-media
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md’s runtime workflow ingests user-provided narration text (script → ElevenLabs
text_to_speech.convert(text=...)) and may also ingest user-provided scene prompts via the delegated “one prompt per scene” flow, so outsider-authored free text is directly passed to the LLM-capable external model calls.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata