longform-video-clone-edit

Warn

Audited by Snyk on Apr 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly downloads arbitrary YouTube videos (Step 1: yt-dlp "YOUTUBE_URL") and then transcribes and analyzes those user-generated/public video frames and text (Steps 2, 6–8) to drive segmentation, HeyGen generation, and compositing decisions, so untrusted third‑party content can directly influence agent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 8, 2026, 08:20 AM
Issues
1
Security Audit — snyk — longform-video-clone-edit