aimlapi-media-gen
Warn
Audited by Snyk on Mar 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's scripts and docs (scripts/gen_video.py, scripts/gen_image.py, SKILL.md, and references/aimlapi-media.md) make live HTTP calls to external AIMLAPI endpoints and arbitrary image/video URLs (including user-provided image-url values and the API-returned video.url) and parse those JSON responses/statuses to drive polling, decisions, and automatic downloads, exposing the agent to untrusted third-party content that can influence runtime actions.
Audit Metadata