aliyun-kling-video

Warn

Audited by Snyk on Apr 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill accepts arbitrary public media URLs (first_frame/last_frame/refer/base/feature) — see scripts/generate_kling_video.py CLI args and SKILL.md Workflow step 3 — and passes them (and prompt references like <<<image_1>>>) to the remote Kling API to be interpreted, so untrusted third‑party content can materially influence generation and agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 4, 2026, 02:31 PM
Issues
1