batch-save

Warn

Audited by Snyk on Mar 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). Step 3 explicitly fetches content from arbitrary public URLs (curl for web pages and defuddle/FxTwitter for YouTube/X posts) and Step 4 launches subagents to read and act on that fetched, user-generated third‑party content as part of the save workflow, so untrusted web/social content can materially influence agent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 05:01 AM
Issues
1
Security Audit — snyk — batch-save