verify-content-credentials

Warn

Audited by Snyk on Aug 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). In the required runtime workflow, scripts/verify_c2pa.py calls provenance_core.run_report (via core.parse_tool_json/classify) on stdout/stderr generated by the locally executed c2patool over a user-supplied asset path (and optional user-supplied trust-anchor URL/path), but it does not ingest outsider-authored free text from any public feed/queue without selecting a specific submitted file/asset.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 13, 2026, 02:05 PM
Issues
1
Security Audit — snyk — verify-content-credentials