meeting-minutes

Warn

Audited by Snyk on Mar 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly supports downloading an arbitrary user-provided URL in Step 0 ("User provided a URL — Download the file using curl -sL <url> -o meetings/tmp/transcript.vtt"), and downstream subagents (Steps 2–4) read and act on that transcript file as part of the required workflow, so untrusted third-party content from arbitrary URLs can directly influence extraction, structuring, and tool actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 19, 2026, 06:28 PM
Issues
1