Transcription Automation
Warn
Audited by Snyk on Mar 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly ingests public third‑party content—e.g., YouTube videos (youtube_subtitles: download_audio source: youtube_video), podcast RSS feeds (podcast_workflow: input: source: rss_feed), and Zoom cloud recordings (zoom_transcription: download_recording source: zoom_cloud)—and then transcribes, extracts action items, generates/distributes outputs, and thus allows untrusted user-generated content to be read and to materially influence downstream actions.
Audit Metadata