vfx

Warn

Audited by Snyk on Jul 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). Yes: the workflow ingests the OUTSIDER-provided video content and audio via runtime URLs (e.g., state.clip_url from a user-supplied public URL or uploaded file) into LLM-readable text through analyze_media and transcribe_audio, then incorporates that readout into the agent’s subsequent LLM prompt (Step 4 → Step 5).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 21, 2026, 02:33 PM
Issues
1
Security Audit — snyk — vfx