ascend-model-migration

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's workflow (SKILL.md and model-migration/ and ascend-mmlab-install-suite/SKILL.md) explicitly instructs the agent to git clone open-source repositories from public sites (e.g., https://gitcode.com/Ascend/DrivingSDK and https://github.com/...), apply patches, and run their scripts on the target server—i.e., it fetches and executes untrusted, user-generated third‑party code that can materially affect tool use and next actions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 07:06 AM
Issues
2