pr-to-video
Warn
Audited by Snyk on Jun 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). Outsider-authored PR content is ingested at runtime into LLM context via
capture/extracted/visible-text.txtandcapture/diff.patch(Step 1:gh pr view/gh pr diff→fetch-pr.mjs→ingest.mjs), which the orchestrator then uses to generateSTORYBOARD.md/SCRIPT.md(LLM prompt injection surface from PR body/diff text).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata