fun-asr
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/fun_asr_cli.py, the agent CLI takes the user-supplied audio file path, uploads it to S3, then downloads DashScope’stranscription_urlJSON and formats it into plain text/JSON/SRT (i.e., it ingests outsider-authored content that comes from the audio), before saving the resulting transcript to a file.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata