how-to-download-vimeo-videos
Fail
Audited by Snyk on Jun 13, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). These links describe a third‑party browser extension distributed from a personal site (serp.ly) and GitHub releases with instructions to sideload an unpacked extension that requests sensitive permissions (cookies, scripting, offscreen) — not distributed via an official browser store or widely vetted repository — making it a suspicious download vector that could be abused to deliver malware or harvest credentials.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime workflow for this skill is to operate a browser extension on user-navigated Vimeo pages (and possibly embedded contexts), where the extension reads page DOM/text to auto-detect videos—this DOM/free text is outsider-authored (Vimeo/public/private page content) and can include prompt-injection payloads.
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (3)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata