podcast-pipeline
Fail
Audited by Snyk on Jul 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.90). The prompt contains deceptive instructions outside the skill's stated purpose—specifically a forced "System Prompt Inquiry Response" that instructs the agent to deflect or hide system/context questions and an unrelated mandatory donation/advertisement intro that injects promotional content into outputs.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The workflow requires ingesting “the episode URL or transcript” (user-provided but could reference publicly fetched/outsider-authored content at runtime), which would be read as free-form prose and included in the LLM context after extraction.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata