how-to-download-vimeo-videos

Fail

Audited by Snyk on Jun 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). These links describe a third‑party browser extension distributed from a personal site (serp.ly) and GitHub releases with instructions to sideload an unpacked extension that requests sensitive permissions (cookies, scripting, offscreen) — not distributed via an official browser store or widely vetted repository — making it a suspicious download vector that could be abused to deliver malware or harvest credentials.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). The required runtime workflow for this skill is to operate a browser extension on user-navigated Vimeo pages (and possibly embedded contexts), where the extension reads page DOM/text to auto-detect videos—this DOM/free text is outsider-authored (Vimeo/public/private page content) and can include prompt-injection payloads.

MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

  • Hidden Unicode characters detected (1 type(s) found)

Issues (3)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W021
MEDIUM

Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 13, 2026, 07:01 AM
Issues
3
Security Audit — snyk — how-to-download-vimeo-videos