afa-convert

Warn

Audited by Snyk on May 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). Yes — the core workflow requires ingesting user-provided/public website content and user-generated signals (e.g., "只有网站 URL" Level 3 heuristic audits in references/anti-patterns.md and Phase 2 数据收集 in SKILL.md, plus session recordings/UGC/competitor site analysis in references/ab-testing-playbook.md), so the agent is expected to read and act on untrusted third‑party pages/content as part of its decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 8, 2026, 12:58 AM
Issues
1
Security Audit — snyk — afa-convert