openclaw-media-gen

Warn

Audited by Snyk on Feb 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill accepts arbitrary external image URLs via the --img-url parameter (used in video_create_task in scripts/media_gen_client.py) and downloads/forwards those third-party images (and can download resulting video URLs via _download_to_file), so untrusted public content is ingested and used by the generation workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 14, 2026, 06:01 PM