ai-avatar-video
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The runtime workflow is the RunComfy CLI invocation where the agent posts the user-provided
prompt/audio_url/image_url(and optional reference assets) intoruncomfy run, and any indirect prompt-injection surface comes from untrusted URLs but only those explicitly provided by the user, not from a queue/feed/search/inbox the outsider can push into for free.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata