bulk
Warn
Audited by Snyk on Jun 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text is ingested when the skill scrapes TikTok profile pages at runtime (public web content) to obtain video titles/metadata and then reads the resulting downloaded transcripts from
transcripts/into the LLM during Step 6 summarization (“Read each transcript file fromtranscripts/directory”).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata