zoom-lecture-publish

Warn

Audited by Snyk on May 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches Zoom cloud recordings, VTT transcripts, and Zoom chat via the Zoom cloud recordings API (see "Zoom録画→note記事だけ分岐" steps and the references/aiplayguild-production-runbook.md "Zoom search and matching"), then reads and summarizes those VTT/chat contents and extracts URLs/questions to drive article creation and publication decisions, so untrusted user-generated third-party content is ingested and can materially influence actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 16, 2026, 12:42 PM
Issues
1
Security Audit — snyk — zoom-lecture-publish