solo-you2idea-extract

Warn

Audited by Snyk on Feb 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly indexes and ingests public YouTube content and transcripts (solograph-cli index-youtube, web_search(engines="youtube"), and yt-dlp -> VTT fetch in the "fetch-transcripts" / make fetch-transcripts step) and then analyzes that user-generated content to extract ideas and drive subsequent actions, so untrusted third-party content can influence the agent's decisions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 21, 2026, 05:54 PM