verify-content-credentials
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In the required runtime workflow, scripts/verify_c2pa.py calls provenance_core.run_report (via core.parse_tool_json/classify) on stdout/stderr generated by the locally executed c2patool over a user-supplied asset path (and optional user-supplied trust-anchor URL/path), but it does not ingest outsider-authored free text from any public feed/queue without selecting a specific submitted file/asset.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata