Transcription Automation

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly ingests public third‑party content—e.g., YouTube videos (youtube_subtitles: download_audio source: youtube_video), podcast RSS feeds (podcast_workflow: input: source: rss_feed), and Zoom cloud recordings (zoom_transcription: download_recording source: zoom_cloud)—and then transcribes, extracts action items, generates/distributes outputs, and thus allows untrusted user-generated content to be read and to materially influence downstream actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 08:23 AM