autocliper-ai
Warn
Audited by Snyk on Jun 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). Outsider free text is ingested from YouTube at runtime via
corekit.fetch_source(yt-dlp downloads auto-/user subtitles from the provided URL intostudio/<slug>/intake/*.srt, thencorekit.subtitle_to_jsonreads that SRT text intotranscript.jsonfor the agent’s analysis context).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata