content-director

Warn

Audited by Snyk on Jun 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The playbooks explicitly fetch and rehost social media reference videos at runtime (e.g., direct TikTok/Instagram video/profile URLs like https://www.tiktok.com/@{handle} and https://www.instagram.com/{handle}/ and direct TikTok/IG video URLs) and pass those fetched clips as motion-reference inputs (e.g., "motion locked to @Video1") to the generation pipeline, so remote content is required at runtime and directly controls model prompts/behavior.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 06:28 PM
Issues
1
Security Audit — snyk — content-director