tavern-design
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). tavern-design 在“材料转化”流程中会通读用户提供的现成叙事素材(轻小说/游戏脚本/小说等)并提取其中原文引用与信息,用于生成
cards/{Project}/故事大纲.yaml与cards/{Project}/design-spec.md,从而让 LLM 在运行时摄入外部用户文本。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata