beat-sync-video-editing

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill uploads and/or fetches arbitrary user-provided media for analysis via ${CLAUDE_PLUGIN_ROOT}/scripts/gemini-edit-plan.sh (supports --video, --audio and --video-uri/--audio-uri) so the agent ingests untrusted third-party audio/video content that Gemini processes to produce the EditPlan.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 02:08 AM