zhang-yiming-perspective

Fail

Audited by Snyk on Aug 25, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.85). Multiple URLs point to a single individual’s GitHub repos (personal/third‑party code) that the README instructs users to clone/install — a common vector for delivering arbitrary code, so these are potentially high‑risk download sources.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该技能在运行时的 Step 2 要“必须使用工具(WebSearch等)获取真实信息”,因此当用户输入的问题触发研究时,工作流会读取由 WebSearch 返回的外部网页/摘要等自由文本(间接提示注入风险中等)。

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 25, 2026, 03:16 AM
Issues
2
Security Audit — snyk — zhang-yiming-perspective