deep-research

Warn

Audited by Snyk on May 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL explicitly instructs the agent to perform multi‑hop web searches and fetch/read arbitrary public webpages (via "WebSearch / WebFetch / Playwright" and the "页面抓取策略" / Playwright steps in SKILL.md §1.5 and §2.3), so it will ingest untrusted user‑generated/public third‑party content and use it to drive hypotheses, verification and report decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 16, 2026, 04:36 AM
Issues
1
Security Audit — snyk — deep-research