video-downloader
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly downloads videos and ingests metadata (title, description, thumbnail) from public, user-generated platforms like YouTube as described in SKILL.md ("Downloads Videos: Fetches videos from YouTube and other platforms" and "Metadata Preservation: Saves title, description, and thumbnail"), meaning it consumes untrusted third‑party content that the agent reads and could influence filenames/processing and thus enable indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata