audio-transcriber

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly accepts and downloads audio from arbitrary URLs ("Step 1: Accept file path or URL" in SKILL.md, e.g., "https://example.com/audio.mp3") and then transcribes that untrusted, user-supplied content and feeds the transcript into LLM processing (SKILL.md Step 3 and scripts/transcribe.py process_with_llm), so third‑party content can directly influence generated summaries, decisions, and action items.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 04:41 PM
Issues
1