usd-inspect-and-provenance

Warn

Audited by Snyk on Aug 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The runtime workflow reads an absolute caller-supplied USD stage file from --stage (via Usd.Stage.Open() and dependency computation with UsdUtils.ComputeAllDependencies), so an outsider who can submit or cause the stage/package contents to be provided can inject malicious free text through USD layer/prim metadata that the inspector ingests at runtime.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 22, 2026, 06:05 PM
Issues
1
Security Audit — snyk — usd-inspect-and-provenance