review-music

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In src/analysis/llm_analyzer.py, runtime transcription/feature text derived from outsider-provided audio input (local file path or --youtube URL downloaded audio; lyrics text included) is formatted into the LLM prompt (features['lyrics']['text'] → format_features_for_prompt → create_analysis_prompt) and then sent to the LLM via the /assistant gateway/scillm completion, so attacker-controlled free text can reach the model through the lyrics field.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:04 PM
Issues
1
Security Audit — snyk — review-music