alibabacloud-website-probe

Warn

Audited by Snyk on Aug 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In SKILL.md the skill submits and then reads network-probing results from the public backend boce.aliyun.com (via scripts/boce_tool.py polling JSON task results, then analyzes/prints it in scripts/boce_wrapper.py and scripts/analyze_boce_dns.py / scripts/analyze_boce_http.py), and that runtime-ingested JSON can include arbitrary human-readable fields like message/route originating from the target responses/error text.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 02:10 AM
Issues
1
Security Audit — snyk — alibabacloud-website-probe