face-swap
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The face-swap skill’s runtime flow classifies the user intent and then invokes
runcomfy run <model_id>with--inputcontaining user-suppliedimage_url/identity_url/audio/video URLs; the CLI later fetches those untrusted reference assets (potentially including their embedded text/media metadata) to generate output.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata