tts-train
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill’s workflow and examples explicitly fetch and ingest public web resources (e.g., SKILL.md’s “Web-Enhanced Bayesian Tuning” with --use_web_research, model downloads from Hugging Face/ModelScope, and example code that loads remote audio URLs like qianwen-res.oss-cn-beijing.aliyuncs.com and httpx.get in examples/test_tokenizer_12hz.py), so untrusted third-party content is read and used to influence tuning, data ingestion, and generation decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata