screen-recorder
Warn
Audited by Snyk on May 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill explicitly navigates to caller-supplied URLs (see Phase 1
urlinput and the generated script's page.goto in templates/record.mjs.template) including public preview/staging hosts passed by thereviewercaller (rules/integrations.md), captures user-generated page content as a video, and that recording is then fed to the downstreamvideo-analyserworkflow (rules/integrations.md) which can produce findings and recommended next actions — i.e., untrusted third-party content is fetched and can materially influence subsequent tool decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata