anibon-timestamper-local

Warn

Audited by Snyk on Aug 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In anibon-timestamper-local Step 2→Step 3, the workflow downloads a YouTube auto-subtitle transcript via yt-dlp from a user-provided VIDEO_URL, chunks it, then the LLM reads each [WORKSPACE]/chunks/chunk_XX.txt (created from that outsider-authored transcript text) to generate and write summarized timestamps.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 04:35 PM
Issues
1
Security Audit — snyk — anibon-timestamper-local