video-content

Warn

Audited by Snyk on Jul 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). SKILL.md Phase 1/4 reads handoff YAML and content spec YAML (e.g., marketing/handoffs/{name}-handoff.yaml and marketing/content-specs/{project}-{framework}.yaml) and then uses their fields (including brand_snapshot, content_spec, and slide text/archetypes) to generate Remotion/ffmpeg parameters—so if those YAMLs were authored by outsiders (e.g., /paper-marketing or /slideshow-script), their free-text fields flow into the LLM context at runtime.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 14, 2026, 02:07 PM
Issues
1
Security Audit — snyk — video-content