deepstream-import-vision-model
Warn
Audited by Snyk on Aug 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow ingests outsider-authored free text from HuggingFace model assets by calling the HF tree API and downloading
config.json/labels during Step 1–3 (viascripts/model/hf-list-files.shandscripts/model/hf-download-config.sh, then parsingconfig.jsoncontent inmodel-acquire.md).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata